{"id":683,"date":"2023-02-27T16:47:55","date_gmt":"2023-02-27T16:47:55","guid":{"rendered":"https:\/\/www.softwaredefinedautomation.io\/?page_id=683"},"modified":"2026-05-13T12:21:28","modified_gmt":"2026-05-13T12:21:28","slug":"exhibit-c","status":"publish","type":"page","link":"https:\/\/www.softwaredefinedautomation.io\/sda-old\/exhibit-c\/","title":{"rendered":"Exhibit C"},"content":{"rendered":"<div class=\"elementor-element elementor-element-4c1137f elementor-widget elementor-widget-aux_modern_heading\" data-id=\"4c1137f\" data-element_type=\"widget\" data-widget_type=\"aux_modern_heading.default\">\n<div class=\"elementor-widget-container\">\n<section class=\"aux-widget-modern-heading\">\n<div class=\"aux-widget-inner\">\n<h2 class=\"aux-modern-heading-description\">Data Processing Addendum<\/h2>\n<\/div>\n<\/section>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-a5b2e79 elementor-widget elementor-widget-text-editor\" data-id=\"a5b2e79\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n<div class=\"elementor-widget-container\">\n<p>The Data Processing Addendum set forth in this\u00a0<u>Exhibit C<\/u>\u00a0(this \u201c<strong>DPA<\/strong>\u201d)<\/p>\n<h2>1. DEFINITIONS<\/h2>\n<p><span style=\"font-weight: 400;\">Unless expressly stated otherwise, capitalized terms used in this DPA have the meanings given below or, if not defined in this DPA, have the meanings given to them elsewhere in this Agreement.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u201c<\/span><b>Applicable Data Protection Laws<\/b><span style=\"font-weight: 400;\">\u201d means the privacy, data protection and data security laws and regulations of any jurisdiction applicable to the Processing of Customer Personal Data under this Agreement, including GDPR and CCPA (as applicable).\u00a0\u00a0\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u201c<\/span><b>CCPA<\/b><span style=\"font-weight: 400;\">\u201d means the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 (the \u201c<\/span><b>CPRA<\/b><span style=\"font-weight: 400;\">\u201d), and any regulations promulgated thereunder.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u201c<\/span><b>Controller<\/b><span style=\"font-weight: 400;\">\u201d means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u201c<\/span><b>Customer Personal Data<\/b><span style=\"font-weight: 400;\">\u201d means any Personal Data that Customer makes available to SDA for Processing to perform the Services.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u201c<\/span><b>Data Subject<\/b><span style=\"font-weight: 400;\">\u201d means the identified or identifiable natural person to whom Customer Personal Data relates.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u201c<\/span><b>Data Subject Request<\/b><span style=\"font-weight: 400;\">\u201d means the request of a Data Subject to exercise rights under Applicable Data Protection Laws in respect of Customer Personal Data in SDA\u2019s possession, custody or control.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u201c<\/span><b>EEA<\/b><span style=\"font-weight: 400;\">\u201d means the European Economic Area.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u201c<\/span><b>GDPR<\/b><span style=\"font-weight: 400;\">\u201d means, as and where applicable to Processing concerned (i) the General Data Protection Regulation (Regulation (EU) 2016\/679) (\u201c<\/span><b>EU GDPR<\/b><span style=\"font-weight: 400;\">\u201d) and\/or (ii) the EU GDPR as it forms part of UK law by virtue of section 3 of the European Union (Withdrawal) Act 2018 (as amended, including by the Data Protection, Privacy and Electronic Communications (Amendments etc.) (EU Exit) Regulations 2019) (\u201c<\/span><b>UK GDPR<\/b><span style=\"font-weight: 400;\">\u201d), including, in each case (i) and (ii), any applicable national implementing or supplementary legislation (e.g., the UK Data Protection Act 2018), and any successor, amendment or re-enactment, to or of the foregoing. References to \u201c<\/span><b>Articles<\/b><span style=\"font-weight: 400;\">\u201d and \u201c<\/span><b>Chapters<\/b><span style=\"font-weight: 400;\">\u201d of, and other relevant defined terms in, the GDPR shall be construed accordingly.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u201c<\/span><b>Personal<\/b> <b>Data<\/b><span style=\"font-weight: 400;\">\u201d means \u201cpersonal data,\u201d \u201cpersonal information,\u201d \u201cpersonally identifiable information\u201d or similar terms defined in Applicable Data Protection Laws.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u201c<\/span><b>Personal Data Breach<\/b><span style=\"font-weight: 400;\">\u201d means a breach of SDA\u2019s security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data in SDA\u2019s possession, custody or control.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u201c<\/span><b>Process<\/b><span style=\"font-weight: 400;\">\u201d and inflections thereof refer to any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure and destruction.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u201c<\/span><b>Processor<\/b><span style=\"font-weight: 400;\">\u201d means a natural or legal person, public authority, agency, or other body which Processes Personal Data on behalf of the Controller.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u201c<\/span><b>Restricted Transfer<\/b><span style=\"font-weight: 400;\">\u201d means any transfer of Customer Personal Data to any person located in (i) in the context of the EEA, any country or territory outside the EEA which does not benefit from an adequacy decision from the European Commission described in Chapter 45 of the GDPR (an \u201c<\/span><b>EU Restricted Transfer<\/b><span style=\"font-weight: 400;\">\u201d) and (ii) in the context of the UK, any country or territory outside the UK, which does not benefit from an adequacy decision from the UK Government (a \u201c<\/span><b>UK Restricted Transfer<\/b><span style=\"font-weight: 400;\">\u201d), in each case, which would be prohibited without a legal basis under Chapter V of the GDPR.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u201c<\/span><b>SCCs<\/b><span style=\"font-weight: 400;\">\u201d means the standard contractual clauses approved by the European Commission pursuant to implementing Decision (EU) 2021\/914.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u201c<\/span><b>Service Data<\/b><span style=\"font-weight: 400;\">\u201d means any data relating to the use, support and\/or operation of the Services, which is collected directly by SDA from and\/or about Users of the Services and\/or Customer\u2019s use of the Services for its own purposes (certain of which may constitute Personal Data).<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u201c<\/span><b>Subprocessor<\/b><span style=\"font-weight: 400;\">\u201d means any third party engaged directly or indirectly by or on behalf of SDA to Process Customer Personal Data under SDA\u2019s care, custody or control.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u201c<\/span><b>Supervisory Authority<\/b><span style=\"font-weight: 400;\">\u201d means (i) in the context of the EEA and the EU GDPR, \u201csupervisory authority\u201d as defined in the EU GDPR; and (ii) in the context of the UK and the UK GDPR, means the UK Information Commissioner\u2019s Office.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u201c<\/span><b>UK Transfer Addendum<\/b><span style=\"font-weight: 400;\">\u201d means the template Addendum B.1.0 issued by the ICO and laid before Parliament in accordance with s119A of the Data Protection Act 2018 on 2 February 2022, as it is revised under Section 18 of the Mandatory Clauses included in Part 2 thereof (the \u201c<\/span><b>UK Mandatory Clauses<\/b><span style=\"font-weight: 400;\">\u201d).<\/span><\/p>\n<h2>2. SCOPE OF THIS DATA PROCESSING ADDENDUM<\/h2>\n<p>2.1 The Parties acknowledge and agree that the details of SDA\u2019s Processing of Customer Personal Data (including the respective roles of the Parties relating to such Processing) are as described in Annex 1 (Data Processing Details) to this DPA.<\/p>\n<p>2.2 Annex 2 (European Annex) to this DPA applies to SDA\u2019s Processing of Customer Personal Data that is subject to the GDPR.<\/p>\n<p>2.3 Annex 3 (California Annex) to this DPA applies to SDA\u2019s Processing of Customer Personal Data that is subject to the CCPA.<\/p>\n<p>2.4 <span style=\"font-weight: 400;\">Section 9 of this DPA applies to SDA\u2019s Processing of Customer Personal Data to the extent required under any requirements of Applicable Data Protection Laws for contracts with Processors, and in such cases, only in respect of Processing subject to such laws.<\/span><\/p>\n<h2>3. PROCESSING OF CUSTOMER PERSONAL DATA<\/h2>\n<p>3.1 <span style=\"font-weight: 400;\">SDA shall not Process Customer Personal Data other than on Customer\u2019s instructions or as required by applicable laws (or in the case of Customer Personal Data subject to the GDPR, the laws of the UK or European Union, as applicable, to which SDA is subject).\u00a0 Customer instructs SDA to Process Customer Personal Data to provide the Services and as authorized by this Agreement.\u00a0 This Agreement is a complete expression of such instructions, and Customer\u2019s additional instructions will be binding on SDA only pursuant to an amendment to this DPA signed by both Parties.\u00a0 Where SDA receives an instruction from Customer that, in its reasonable opinion, violates Applicable Data Protection Laws, SDA shall notify Customer.<\/span><\/p>\n<p>3.2 <span style=\"font-weight: 400;\">The Parties acknowledge that SDA\u2019s Processing of Customer Personal Data authorized by Customer\u2019s instructions stated in this DPA are integral to the Services and the business relationship between the Parties. Access to Personal Data does not form part of the consideration exchanged between the Parties in respect of this Agreement or any other business dealings.<\/span><\/p>\n<h2>4. VENDOR PERSONNEL<\/h2>\n<p><span style=\"font-weight: 400;\">SDA shall ensure that all SDA employees or other personnel who Process Customer Personal Data are subject to contractual or appropriate statutory obligations of confidentiality with respect to such Customer Personal Data.<\/span><\/p>\n<h2>5. SECURITY<\/h2>\n<p><span style=\"font-weight: 400;\">SDA shall implement and maintain technical, organizational and physical measures designed to protect the confidentiality, integrity and availability of Customer Personal Data and prevent Personal Data Breaches.\u00a0 Such measures shall include the measures described in Annex 4 of this DPA (the \u201c<\/span><b>Security Measures<\/b><span style=\"font-weight: 400;\">\u201d) and such other measures as are required by Applicable Data Protection Laws.\u00a0 SDA may update the Security Measures from time to time, so long as the updated measures do not decrease in the aggregate the protection of Personal Data.<\/span><\/p>\n<h2>6. DATA SUBJECT REQUESTS<\/h2>\n<p>6.1 <span style=\"font-weight: 400;\">SDA, taking into account the nature of the Processing of Customer Personal Data, shall provide Customer with such assistance by appropriate technical and organizational measures as Customer may reasonably request to assist Customer in fulfilling its obligations under Applicable Data Protection Laws to respond to Data Subject Requests. <\/span><\/p>\n<p>6.2 <span style=\"font-weight: 400;\">SDA shall promptly notify Customer if it receives a Data Subject Request and not respond to any Data Subject Request, other than to advise the Data Subject to submit the request to Customer, except as required by Applicable Data Protection Laws.<\/span><\/p>\n<h2>7. PERSONAL DATA BREACHES<\/h2>\n<p>7.1 <span style=\"font-weight: 400;\">SDA shall notify Customer of a Personal Data Breach without undue delay after becoming aware of the occurrence thereof. SDA\u2019s notification of or response to a Personal Data Breach will not be construed as SDA\u2019s acknowledgement of any fault or liability with respect to the Personal Data Breach. Customer is solely responsible for complying with notification laws applicable to Customer and fulfilling any third-party notification obligations related to any Personal Data Breaches.<\/span><\/p>\n<p>7.2 <span style=\"font-weight: 400;\">If Customer determines that a Personal Data Breach must be notified to any Supervisory Authority or other governmental authority, any Data Subject(s), the public or others under Applicable Data Protection Laws in a manner that directly or indirectly refers to or identifies SDA, where permitted by applicable laws, Customer agrees to notify SDA in advance and in good faith consult with SDA and consider any clarifications or corrections SDA may reasonably recommend or request to any such notification.<\/span><\/p>\n<h2>8 SUB-PROCESSING<\/h2>\n<p>8.1 Customer generally authorizes SDA to appoint Subprocessors in accordance with this Section 8. Without limitation to the foregoing, Customer authorizes the engagement of the Subprocessors listed as of the effective date of this Agreement at the URL specified in 2.<\/p>\n<p>8.2 Information about Subprocessors, including their functions and locations, is available at: <a href=\"https:\/\/www.softwaredefinedautomation.io\/sda-old\/privacy-policy\/\">https:\/\/www.softwaredefinedautomation.io\/sda-old\/privacy-policy\/<\/a>\u00a0(as may be updated by SDA from time to time) or such other website address as SDA may provide to Customer from time to time (the \u201c<strong>Subprocessor Site<\/strong>\u201d).<\/p>\n<p>8.3 When engaging any Subprocessor, SDA will enter into a written contract with such Subprocessor containing data protection obligations not less protective than those in this DPA with respect to Customer Personal Data where required by Applicable Data Protection Laws and to the extent applicable to the nature of the services provided by such Subprocessor. SDA shall be liable for all obligations under this Agreement subcontracted to the Subprocessor or its actions and omissions related thereto.<\/p>\n<p>8.4 When SDA engages any Subprocessor after the effective date of this Agreement, SDA will notify Customer of the engagement (including the name and location of the relevant Subprocessor and the activities it will perform) by updating the Subprocessor Site or by other written means at least 15 days before such Subprocessor Processes Customer Personal Data. If Customer objects to such engagement in a written notice to SDA within 15 days after being notified of the engagement on reasonable grounds relating to the protection of Personal Data, Customer and SDA will work together in good faith to consider a mutually acceptable resolution to such objection.\u00a0 If the parties are unable to reach a mutually acceptable resolution within a reasonable timeframe, Customer may, as its sole and exclusive remedy, terminate this Agreement and cancel the Services by providing written notice to SDA and pay SDA for all amounts due and owing under this Agreement as of the date of such termination. If Customer does not object to SDA\u2019s appointment of a Subprocessor during the objection period referred to in this Paragraph 8.4, Customer shall be deemed to have approved the engagement and ongoing use of that Subprocessor.<\/p>\n<h2>9. COMPLIANCE ASSISTANCE; AUDITS<\/h2>\n<p>9.1 SDA, taking into account the nature of the Processing and the information available to SDA, shall provide such information and assistance as Customer may reasonably request (insofar as such information is available to SDA and the sharing thereof does not compromise the security, confidentiality, integrity or availability of Personal Data Processed by SDA) to help Customer meet its obligations under Applicable Data Protection Laws, including in relation to the security of Customer Personal Data, the reporting and investigation of Personal Data Breaches, the demonstration of Customer\u2019s compliance with such obligations, and the performance of any data protection assessments and consultations with Supervisory Authorities or other government authorities regarding such assessments in relation to SDA\u2019s Processing of Customer Personal Data, including those required under Articles 35 and 36 of the GDPR.<\/p>\n<p>9.2 SDA shall make available to Customer such information as Customer may reasonably request for SDA to demonstrate compliance with Applicable Data Protection Laws and this DPA. Without limitation of the foregoing, Customer may conduct (in accordance with Section 3 below), at its sole cost and expense, and SDA will reasonably cooperate with, reasonable audits (including inspections, manual reviews, and automated scans and other technical and operational testing that Customer is entitled to perform under Applicable Data Protection Laws), in each case, whereby Customer or a qualified and independent auditor appointed by Customer using an appropriate and accepted audit control standard or framework may audit SDA\u2019s technical and organizational measures in support of such compliance and the auditor\u2019s report is provided to Customer and SDA upon Customer\u2019s request.<\/p>\n<p>9.3 Customer shall give SDA reasonable advance notice of any such audits. SDA need not cooperate with any audit (a) performed by any individual or entity who has not entered into a non-disclosure agreement with SDA on terms acceptable to SDA in respect of information obtained in relation to the audit; (b) outside normal business hours; or (c) on more than one occasion in any calendar year during the term of this Agreement, except for any additional audits that Customer is required to perform under Applicable Data Protection Laws.\u00a0 The audit must be conducted in accordance with SDA\u2019s safety, security or other relevant policies, must not impact the security, confidentiality, integrity or availability of any data Processed by SDA and must not unreasonably interfere with SDA\u2019s business activities.\u00a0 Customer shall not conduct any scans or technical or operational testing of SDA\u2019s applications, websites, Services, networks or systems without SDA\u2019s prior approval (which shall not be unreasonably withheld).<\/p>\n<p>9.4 If the controls or measures to be assessed in the requested audit are assessed in a SOC 2 Type 2, ISO, NIST or similar audit report performed by a qualified and independent third-party auditor pursuant to a recognized industry standard audit framework within twelve (12) months of Customer\u2019s audit request (\u201c<strong>Audit Report<\/strong>\u201d) and SDA has confirmed in writing that there have been no known material changes to the controls audited and covered by such Audit Report(s), Customer agrees to accept provision of such Audit Report(s) in lieu of requesting an audit of such controls or measures. SDA shall provide copies of any such Audit Reports to Customer upon request.<\/p>\n<p>9.5 Such Audit Reports and any other information obtained by Customer in connection with an audit under this Section 9 shall constitute confidential information of SDA, which Customer shall use only for the purposes of confirming compliance with the requirements of this DPA or meeting Customer\u2019s obligations under Applicable Data Protection Laws. Nothing in this Section 9 shall be construed to obligate SDA to breach any duty of confidentiality, including (without limitation) any such duty owed to SDA\u2019s other customers or other third parties.<\/p>\n<h2>10. RETURN AND DELETION<\/h2>\n<p>10.1 Upon termination of this Agreement, SDA shall return and\/or delete all Customer Personal Data in SDA\u2019s care, custody or control within a reasonable period of time.<\/p>\n<p>10.2 Notwithstanding the foregoing, SDA may retain Customer Personal Data where required by law (or in the case of Customer Personal Data subject to the GDPR, the laws of the UK or European Union, as applicable), provided that SDA shall (a) maintain the confidentiality of all such Customer Personal Data and (b) Process Customer Personal Data only as necessary for the purpose(s) and duration specified in the applicable law requiring such retention.<\/p>\n<h2>11. CUSTOMER RESPONSIBILITIES<\/h2>\n<p>11.1 Customer agrees that, without limiting SDA\u2019s obligations under Section 5 of this DPA, Customer is solely responsible for its use of the Services, including (a) making appropriate use of the Services to maintain a level of security appropriate to the risk in respect of Customer Data; (b) securing the account authentication credentials, systems and devices Customer uses to access the Services; (c) securing Customer\u2019s systems and devices that SDA uses to provide the Services; and (d) backing up Customer Data.<\/p>\n<p>11.2 Customer shall ensure that there is a valid legal basis for SDA\u2019s Processing of Customer Personal Data in accordance with this Agreement for the purposes of Applicable Data Protection Laws (including Article 6, Article 9(2) and\/or Article 10 of the GDPR where applicable). Customer shall ensure (and is solely responsible for ensuring) that all required notices have been given to, and all consents and permissions have been obtained from, Data Subjects and others as are required, including under Applicable Data Protection laws, for SDA to Process Customer Personal Data as contemplated by this Agreement.<\/p>\n<p>11.3 Customer agrees that the Service, the Security Measures, and SDA\u2019s commitments under this DPA are adequate to meet Customer\u2019s needs, including with respect to any security obligations of Customer under Applicable Data Protection Laws, and provide a level of security appropriate to the risk in respect of Customer Personal Data.<\/p>\n<p>11.4 Customer shall ensure that Customer Personal Data made available to SDA for Processing does not contain any (a) Social Security numbers or other government-issued identification numbers; (b) biometric information; (c) passwords to any online accounts; (d) credentials to any financial accounts; (e) tax return data; (f) any payment card information subject to the Payment Card Industry Data Security Standard; (g) Personal Data of children under 16 years of age; (h) data relating to criminal convictions and offences or related security measures; or (i) information that constitutes special categories of personal data (as defined in the GDPR), sensitive personal information (as defined in the CCPA) or information of a similarly sensitive character regulated by Applicable Data Protection Laws.<\/p>\n<h2>12. LIABILITY<\/h2>\n<p><span style=\"font-weight: 400;\">The total aggregate liability of either Party towards the other Party, howsoever arising, under or in connection with this DPA will under no circumstances exceed any limitations or caps on, and shall be subject to any exclusions of, liability and loss agreed by the Parties in this Agreement.<\/span><\/p>\n<h2>13. SERVICE DATA<\/h2>\n<p>13.1 Customer acknowledges that SDA may collect, use and disclose Service Data for its own business purposes, such as:<\/p>\n<ul>\n<li>for accounting, tax, billing, audit, and compliance purposes;<\/li>\n<li>to provide, improve, develop, optimise and maintain the Services;<\/li>\n<li>to investigate fraud, spam, wrongful or unlawful use of the Services; and\/or<\/li>\n<li>as otherwise permitted or required by applicable law.<\/li>\n<\/ul>\n<p>13.2 In respect of any such Processing described in Section 1 above, SDA:<\/p>\n<ul>\n<li>independently determines the purposes and means of such Processing;<\/li>\n<li>shall comply with Applicable Data Protection Laws (if and as applicable in the context);<\/li>\n<li>shall Process such Service Data as described in SDA\u2019s relevant privacy notices\/policies, as updated from time to time; and<\/li>\n<li>where possible, shall apply technical and organisational safeguards to any relevant Personal Data that are no less protective than the Security Measures.<\/li>\n<\/ul>\n<p>13.3 For the avoidance of doubt, this DPA shall not apply to SDA collection, use, disclosure or other Processing of Service Data, and Service Data does not constitute Customer Personal Data.<\/p>\n<h2>14. CHANGE IN LAWS<\/h2>\n<p>SDA may on notice vary this DPA to the extent that (acting reasonably) it considers necessary to address the requirements of Applicable Data Protection Laws from time to time, including (without limitation) as described in Section 1 of Annex 2 of this DPA.\u00a0 The Parties agree to cooperate in good faith to amend this Agreement or DPA as may be reasonably necessary to address compliance with Applicable Data Protection Laws.<\/p>\n<h2>15. PRECEDENCE<\/h2>\n<p><span style=\"font-weight: 400;\">In the event of any conflict or inconsistency between (a) the provisions in this DPA and any other provisions of this Agreement, this DPA shall prevail or (b) any SCCs entered into in the future pursuant to Section 1 of Annex 2 of this DPA and any provisions of this DPA and\/or any other provisions of this Agreement, the SCCs shall prevail in respect of the Restricted Transfer to which they apply.<\/span><\/p>\n<p><strong>Annex 1 \u2013 Data Processing Details<\/strong><\/p>\n<p><strong><u>CUSTOMER<\/u><\/strong><strong><u>\u00a0DETAILS<\/u><\/strong><\/p>\n<p><strong>Name<\/strong>:\u00a0 As set out in the applicable Order(s)<\/p>\n<p><strong>Contact details for data protection<\/strong>: As set out in the applicable Order(s)<\/p>\n<p><strong>Customer Activities<\/strong>:\u00a0 Manufacturing operations<\/p>\n<p><strong>Role<\/strong>: Controller<\/p>\n<p><strong><u>SDA DETAILS<\/u><\/strong><\/p>\n<p><strong>Name<\/strong>:\u00a0 Software Defined Automation Inc.<\/p>\n<p><strong>Contact details for data protection<\/strong>:\u00a0<a href=\"mailto:privacy@softwaredefinedautomation.io\">privacy@softwaredefinedautomation.io<\/a><\/p>\n<p><strong>SDA Activities<\/strong>:\u00a0 Provider of a software-as-a-service industrial automation platform to organizations\u2019 development and operations teams<\/p>\n<p><strong>Role<\/strong>: Processor<\/p>\n<p><strong><u>DETAILS OF PROCESSING<\/u><\/strong><\/p>\n<p><strong>Categories of Data Subjects:\u00a0<\/strong>Users of the Services<\/p>\n<p><strong>\u00a0<\/strong><\/p>\n<p><strong>Categories of Personal Data:\u00a0<\/strong>Personal Data pertaining to Customer\u2019s employees\u2019 and other Users\u2019 use of and interaction with the Services, which may include: (i) personal details such as business contact data (name, business phone and email, etc.) and (ii) technological details, such as internet protocol (IP) addresses, unique identifies and numbers (including unique identifiers in tracking cookies or similar technologies), pseudonymous identifiers, location data, internet\/application\/program activity data, and device IDs and addresses.<\/p>\n<p><strong>\u00a0<\/strong><\/p>\n<p><strong>Sensitive Categories of Data, and associated additional restrictions\/safeguards:\u00a0<\/strong>Not applicable<\/p>\n<p><strong>Frequency of transfer:\u00a0<\/strong>ongoing<\/p>\n<p><strong>\u00a0<\/strong><\/p>\n<p><strong>Nature and purpose of the Processing:<\/strong>\u00a0Processing operations required in order to provide the Services in accordance with this Agreement. Customer Personal Data will be processed: (i) as necessary to provide the Services as initiated by Customer in its use thereof, and (ii) to comply with any other reasonable instructions provided by Customer in accordance with the terms of this DPA.<\/p>\n<p><strong>Duration of Processing \/ Retention Period:\u00a0\u00a0<\/strong>Concurrent with term of this Agreement and then thereafter pursuant to Section 10 of this DPA<\/p>\n<p><strong>Transfers to Subprocessors:\u00a0\u00a0<\/strong>Transfers to Subprocessors are as, and for the purposes, described from time to time in the Subprocessor List (as may be updated from time to time in accordance with this DPA<strong>).<\/strong><\/p>\n<p><strong>\u00a0<\/strong><\/p>\n<p><strong>Annex 2 \u2013 European Annex<\/strong><\/p>\n<p><strong>1. R<\/strong><strong>ESTRICTED TRANSFERS<\/strong><\/p>\n<p>The Parties acknowledge that should the transmission of Customer Personal Data between SDA and Customer under this Agreement involve a Restricted Transfer, the Parties shall, prior to any such Restricted Transfer taking place, enter into the required contractual transfer mechanism, which may include the SCCs and\/or UK Transfer Addendum, in order to legitimately carry out such Restricted Transfer.<\/p>\n<p><strong>2. LIABILITY TO DATA SUBJECTS<\/strong><\/p>\n<p>Notwithstanding any provision of this Agreement to the contrary, nothing in this Agreement shall limit either Party\u2019s liability to Data Subjects under the third party beneficiary provisions of the SCCs.<\/p>\n<p><strong>Annex 3 \u2013 California Annex<\/strong><\/p>\n<p>Capitalized terms used in this California Annex but not defined in this DPA or elsewhere in this Agreement shall have the meanings given to them in the CCPA. As used in this California Annex, \u201cPersonal Information\u201d means Customer Personal Data that constitutes \u201cpersonal information\u201d under the CCPA.<\/p>\n<p>1. Business Purposes and services: the Business Purposes and services for which SDA is Processing Personal Information are for SDA to provide the Services to and on behalf of Customer as set forth in this Agreement, as described in more detail in Annex 1 of this DPA.<\/p>\n<p>2. It is the Parties\u2019 intent that SDA is a Service Provider with respect to its processing of Customer Personal Data. SDA (a) acknowledges that Personal Information is disclosed by Customer only for limited and specified purposes described in this Agreement; (b) shall comply with applicable obligations under the CCPA and shall provide the same level of privacy protection to Personal Information as is required by the CCPA; (c) agrees that Customer has the right to take reasonable and appropriate steps under Section 9 of this DPA to help to ensure that SDA\u2019s use of Personal Information is consistent with Customer\u2019s obligations under the CCPA; (d) shall notify Customer in writing of any determination made by SDA that it can no longer meet its obligations under the CCPA; and (e) agrees that Customer has the right, upon notice, including pursuant to the preceding clause, to take reasonable and appropriate steps to stop and remediate unauthorized use of Personal Information.<\/p>\n<p>3. SDA shall not (a) Sell or Share Personal Information; (b) retain, use, or disclose any Personal Information for any purpose other than for the Business Purposes specified in this Agreement, including retaining, using, or disclosing Personal Information for a Commercial Purpose other than the Business Purpose specified in this Agreement, or as otherwise permitted by CPPA; (c) retain, use or disclose Personal Information outside of the direct business relationship between SDA and Customer; or (d) combine Personal Information received pursuant to this Agreement with Personal Information (i) received from or on behalf of another person, or (ii) or collected from SDA\u2019s own interaction with any Consumer to whom such Personal Information pertains. SDA hereby certifies that it understands the obligations under this Section and will comply with them.<\/p>\n<p>4. Giving Customer notice of Subprocessor engagements in accordance with Section 8 of this DPA shall satisfy SDA\u2019s obligation under the CPRA to give notice of such engagements.<\/p>\n<p>5. Obligations under this California Annex that are neither required to be imposed on SDA for SDA to qualify as a Service Provider under the CCPA nor for the Parties to comply with their obligations under the CCPA in relation to the required terms of contracts, in each case, before the CPRA takes effect on January 1, 2023, shall apply to SDA only on and after January 1, 2023.<\/p>\n<p><strong>Annex 4 \u2013 Security Measures<\/strong><\/p>\n<p>SDA agrees to implement and maintain the following Security Measures:<\/p>\n<p>1. Audit and risk assessment procedures for the purposes of periodic review and assessment of risks to SDA\u2019s organization, monitoring and maintaining compliance with SDA\u2019s policies and procedures, and reporting the condition of its information security and compliance to internal senior management.<\/p>\n<p>2. Data security controls which include at a minimum logical segregation of data, restricted (e.g., role-based) access and monitoring, and utilisation of commercially available and industry standard encryption technologies for Customer Personal Data.<\/p>\n<p>3. Logical access controls designed to manage electronic access to data and system functionality based on authority levels and job functions.<\/p>\n<p>4. Password controls designed to manage and control password strength, expiration and usage.<\/p>\n<p>5. System audit or event logging and related monitoring procedures to proactively record user access and system activity.<\/p>\n<p>6. Operational procedures and controls to provide for configuration, monitoring and maintenance of technology and information systems, including secure disposal of systems and media to render all information or data contained therein as undecipherable or unrecoverable prior to final disposal or release from SDA\u2019s<\/p>\n<p>7. Network security controls and procedures for network services and components.<\/p>\n<p>8. Vulnerability assessment and threat protection technologies and scheduled monitoring procedures designed to identify, assess, mitigate, and protect against identified security threats, viruses, and other malicious code.<\/p>\n<p>9. Business resiliency\/ continuity and disaster recovery procedures designed to maintain service and\/or recovery from foreseeable emergency situations or disaster.<\/p>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Data Processing Addendum The Data Processing Addendum set forth in this\u00a0Exhibit C\u00a0(this \u201cDPA\u201d) 1. DEFINITIONS Unless expressly stated otherwise, capitalized terms used in this DPA have the meanings given below or, if not defined in this DPA, have the meanings given to them elsewhere in this Agreement. \u201cApplicable Data Protection Laws\u201d means the privacy, data &hellip; <a href=\"https:\/\/www.softwaredefinedautomation.io\/sda-old\/exhibit-c\/\">Continued<\/a><\/p>\n","protected":false},"author":3,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"_acf_changed":false,"inline_featured_image":false,"footnotes":""},"class_list":["post-683","page","type-page","status-publish","hentry"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v25.4 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Exhibit C: \u200b\u200bData Processing Addendum | SDA<\/title>\n<meta name=\"description\" content=\"Learn about our security measures to protect the confidentiality, integrity, and availability of customer data and prevent breaches.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.softwaredefinedautomation.io\/sda-old\/exhibit-c\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Exhibit C: \u200b\u200bData Processing Addendum | SDA\" \/>\n<meta property=\"og:description\" content=\"Learn about our security measures to protect the confidentiality, integrity, and availability of customer data and prevent breaches.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.softwaredefinedautomation.io\/sda-old\/exhibit-c\/\" \/>\n<meta property=\"og:site_name\" content=\"SDA old\" \/>\n<meta property=\"article:modified_time\" content=\"2026-05-13T12:21:28+00:00\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"19 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.softwaredefinedautomation.io\/sda-old\/exhibit-c\/\",\"url\":\"https:\/\/www.softwaredefinedautomation.io\/sda-old\/exhibit-c\/\",\"name\":\"Exhibit C: \u200b\u200bData Processing Addendum | SDA\",\"isPartOf\":{\"@id\":\"https:\/\/www.softwaredefinedautomation.io\/sda-old\/#website\"},\"datePublished\":\"2023-02-27T16:47:55+00:00\",\"dateModified\":\"2026-05-13T12:21:28+00:00\",\"description\":\"Learn about our security measures to protect the confidentiality, integrity, and availability of customer data and prevent breaches.\",\"breadcrumb\":{\"@id\":\"https:\/\/www.softwaredefinedautomation.io\/sda-old\/exhibit-c\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.softwaredefinedautomation.io\/sda-old\/exhibit-c\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.softwaredefinedautomation.io\/sda-old\/exhibit-c\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.softwaredefinedautomation.io\/sda-old\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Exhibit C\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.softwaredefinedautomation.io\/sda-old\/#website\",\"url\":\"https:\/\/www.softwaredefinedautomation.io\/sda-old\/\",\"name\":\"SDA old\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.softwaredefinedautomation.io\/sda-old\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Exhibit C: \u200b\u200bData Processing Addendum | SDA","description":"Learn about our security measures to protect the confidentiality, integrity, and availability of customer data and prevent breaches.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.softwaredefinedautomation.io\/sda-old\/exhibit-c\/","og_locale":"en_US","og_type":"article","og_title":"Exhibit C: \u200b\u200bData Processing Addendum | SDA","og_description":"Learn about our security measures to protect the confidentiality, integrity, and availability of customer data and prevent breaches.","og_url":"https:\/\/www.softwaredefinedautomation.io\/sda-old\/exhibit-c\/","og_site_name":"SDA old","article_modified_time":"2026-05-13T12:21:28+00:00","twitter_card":"summary_large_image","twitter_misc":{"Est. reading time":"19 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.softwaredefinedautomation.io\/sda-old\/exhibit-c\/","url":"https:\/\/www.softwaredefinedautomation.io\/sda-old\/exhibit-c\/","name":"Exhibit C: \u200b\u200bData Processing Addendum | SDA","isPartOf":{"@id":"https:\/\/www.softwaredefinedautomation.io\/sda-old\/#website"},"datePublished":"2023-02-27T16:47:55+00:00","dateModified":"2026-05-13T12:21:28+00:00","description":"Learn about our security measures to protect the confidentiality, integrity, and availability of customer data and prevent breaches.","breadcrumb":{"@id":"https:\/\/www.softwaredefinedautomation.io\/sda-old\/exhibit-c\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.softwaredefinedautomation.io\/sda-old\/exhibit-c\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.softwaredefinedautomation.io\/sda-old\/exhibit-c\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.softwaredefinedautomation.io\/sda-old\/"},{"@type":"ListItem","position":2,"name":"Exhibit C"}]},{"@type":"WebSite","@id":"https:\/\/www.softwaredefinedautomation.io\/sda-old\/#website","url":"https:\/\/www.softwaredefinedautomation.io\/sda-old\/","name":"SDA old","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.softwaredefinedautomation.io\/sda-old\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"}]}},"_links":{"self":[{"href":"https:\/\/www.softwaredefinedautomation.io\/sda-old\/wp-json\/wp\/v2\/pages\/683","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.softwaredefinedautomation.io\/sda-old\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/www.softwaredefinedautomation.io\/sda-old\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/www.softwaredefinedautomation.io\/sda-old\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.softwaredefinedautomation.io\/sda-old\/wp-json\/wp\/v2\/comments?post=683"}],"version-history":[{"count":2,"href":"https:\/\/www.softwaredefinedautomation.io\/sda-old\/wp-json\/wp\/v2\/pages\/683\/revisions"}],"predecessor-version":[{"id":5166,"href":"https:\/\/www.softwaredefinedautomation.io\/sda-old\/wp-json\/wp\/v2\/pages\/683\/revisions\/5166"}],"wp:attachment":[{"href":"https:\/\/www.softwaredefinedautomation.io\/sda-old\/wp-json\/wp\/v2\/media?parent=683"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}