Data Protection Addendum
This Data Protection Addendum (“DPA”) is entered into between the Coalition contracting entity to the Agreement (“Coalition", also referred to as “Processor”) and Client (defined below, also referred to as “Controller”, or may be referred to as “Customer” in the Agreement). Coalition and Client shall each be referred to as a “Party” and collectively as the “Parties”. This DPA is effective as of the effective date of the Agreement (“Effective Date”).
I. Applicability and Effective Date
This DPA is made pursuant to Applicable Privacy Laws (defined below) including but not limited to CCPA (defined below) and GDPR (defined below). This DPA shall amend and be incorporated into any current valid written contracts between the Parties requiring the processing of Personal Data on behalf of Controller by Processor (collectively, the “Agreement”).
II. Definitions
Capitalized terms not otherwise defined herein shall have the meaning given to them under the Agreement or Applicable Privacy Law. In particular, the terms “Commission”, “Controller”, “Personal Data Breach”, “Processor” and “Supervisory Authority” shall have the meaning as set forth in the GDPR. The terms “Data Exporter” and “Data Importer” shall have the same meaning as in the Standard Contractual Clauses. The terms “Business”, “Business Purpose”, “Collects”, “Consumer”, “Contractor”, “Person”, “Processing”, “Sell”, “Service Provider”, and “Share” shall have the meaning set forth in the CCPA. The following terms in the GDPR and CCPA are understood to have the same meaning: “Controller” and “Business”, “Data Subject” and “Consumer”, “Processor” and “Service Provider”, and “Person” and “Subprocessor”.
“Affiliates” means any company that controls, is controlled by, or is under common control with another company.
“Applicable Privacy Laws” means any laws that regulate the Processing, privacy or security of Client Personal Data and that are directly applicable to each Party when Processing Client Personal Data. Applicable Privacy Laws include but are not limited to (i) the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and any local laws implementing or supplementing the GDPR, (ii) the United Kingdom (“UK”) Data Protection Act 2018 and the GDPR as it forms part of the law of England and Wales, Scotland and Northern Ireland by virtue of section 3 of the European Union (Withdrawal) Act 2018 (“UK GDPR”), (iii) the California Consumer Privacy Act of 2018 effective January 1, 2020, and its implementing regulations, as amended or superseded from time to time (“CCPA”), (iv) the Australia Privacy Act 1988 (No. 119 1988), as amended (“Privacy Act”), and the Australian Privacy Principles (“APPs”), (v) Canadian Personal Information Protection and Electronic Documents Act (“PIPEDA”) and substantially similar provincial laws, and (vi) Swiss Data Protection Laws.
“Client” means the person or entity that has entered into the Agreement with Coalition.
“Client Personal Data” means (i) Personal Data as defined under GDPR, (ii) Personal Information, as defined under CCPA, and/or (iii) similar terms as defined under Applicable Privacy Laws processed by Processor, or its Subprocessor (as applicable), on behalf of Client in the provision of the Services pursuant to the Agreement.
“Data Subject” means (i) “data subject” as defined under GDPR, (ii) “consumer” as defined under CCPA, or (iii) similar term under Applicable Privacy Laws.
“EEA” means the member states of the European Union and Iceland, Liechtenstein and Norway.
“EEA SCCs” means Module 2 (Controller to Processor) of the Standard Contractual Clauses for the transfer of personal data to Third Countries set out in Commission Implementing Decision (EU) 2021/914 of 4 June 2021 (and “EEA SCCs” shall be construed accordingly), specifically:
a) the optional docking clause 7 of the EEA SCCs does not apply and is deemed to be deleted;
b) for the purposes of clause 9 of the EEA C2P SCCs, option 2 (General Written Authorisation) applies and the relevant time period is 15 calendar days;
c) the independent dispute resolution option in clause 11 of the EEA SCCs does not apply;
d) for the purposes of clause 17 of the EEA SCCs, the chosen option is option 1 and the chosen law is that set forth under the Agreement. If none provided, the chosen law shall be that of Ireland;
e) for the purposes of clause 18(b) of the EEA SSCs, the chosen courts are courts set forth under the Agreement. If none provided, the chosen courts are those in Ireland;
f) the Appendices of the EEA SCCs shall be completed as follows: 1. Client shall be the controller and data exporter and Coalition shall be the processor and data importer for the purposes of Annex I.A to the EEA SCCs and the contact information for each shall be as follows: (i) Client contact person’s name, position and contact details: as forth in the Agreement; and (ii) Coalition contact person’s name, position and contact details: as set forth in the Agreement. 2. the contents of Exhibit 1 shall form Annex I.B to the EEA SCCs; 3. the competent supervisory authority shall be Ireland for the purposes of Annex I.C to the EEA SCCs; 4. the contents of Exhibit 2 shall form Annex II to the EEA SCCs; and 5. the contents of Exhibit 4 shall form Annex III to the EEA SCCs.
“Restricted Transfer” means any transfer of Client Personal Data by Client to Coalition in a Third Country where (1) the transferring Client entity is established in the UK, EEA or Switzerland and/or (2) the Personal Data originated in the UK, the EEA or Switzerland.
“Sensitive Data” means Personal Data that is protected under a special legislation and requires unique treatment, such as “special categories of data”, “sensitive data” or other materially similar terms under applicable Data Protection Laws, which may include any of the following: (a) social security number, tax file number, passport number, driver’s license number, or similar identifier (or any portion thereof); (b) financial or credit information, credit or debit card number; (c) information revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data or biometric data for the purpose of uniquely identifying a natural person, data concerning a person’s health, sex life or sexual orientation, or data relating to criminal convictions and offences; (d) Personal Data relating to children; and/or (e) account passwords in unhashed form.
“Services” means any and all services or subscriptions provided by Coalition to Client pursuant to the Agreement.
“Standard Contractual Clauses” means the applicable module of the EEA, the Swiss or the UK government-approved contract mechanism for the cross-border transfer of Client Personal Data from the EEA, Switzerland or the UK (as applicable) to Third Countries.
“Swiss SCCs” means the EEA SCCs, as amended as follows: a) general and specific references in the EEA SCCs to Regulation (EU) 2016/679 or “that Regulation” or EU or member state law have the same meaning as the equivalent reference in Swiss Data Protection Law;
b) the term “member state” will not be interpreted in such a way as to exclude Data Subjects in Switzerland from the possibility of suing for their rights in their place of habitual residence (Switzerland) in accordance with clause 18(c) of the EEA SCCs;
c) the details of the transfers are those specified in Schedule 1 where Swiss Data Protection Law apply to the transfer;
d) the EEA SCCs also apply to the transfer of information relating to an identified or identifiable legal entity where such information is protected similarly as “Personal Data” under Swiss Data Protection Laws until such laws are amended to no longer apply to a legal entity; and
e) the Swiss Federal Data Protection and Information Commissioner is the competent supervisory authority for the purposes of clause 13 of the EEA SCCs.
“Swiss Data Protection Law” means the data protection and privacy laws and regulations of Switzerland.
“Third Countries” means countries other than (1) EEA member states; (2) Switzerland; (3) the UK or (4) those subject to an adequacy Client Personal Data by the European Commission and/or the UK Secretary of State (as applicable) from time-to-time.
“UK Addendum” means the International Data Transfer Addendum issued by the Information Commissioners’ Office under s.119(A) of the UK Data Protection Act 2018 as may be updated from time-to-time, currently found at International Data Transfer Addendum to the EU Commission Standard Contractual Clauses.
“UK SCCs” means the UK Addendum, where:
a) Table 1 and Table 3 of the UK Addendum are deemed to have been completed with the corresponding details set out in Exhibit 1 to this DPA and, for the purposes of Table 1 of the UK Addendum, 1. the "Start Date" is the Effective Date; and 2. the official company registration numbers (where applicable) of the Parties are as set out in the Agreement;
b) for the purposes of Table 2 of the UK Addendum, (1) the version of the "Approved EU SCCs" is the EEA SCCs; (2) the choices regarding clause 7 (docking clauses), clause 11 (option), clause 9a (prior authorisation or general authorisation) and clause 9a (time period) of the EEA SCCs are as set out in the definition of EEA SCCs in this DPA; and
c) "Importer" is deemed to have been chosen for the purposes of Table 4 of the UK Addendum.
III. Processing of Client Personal Data
A. Processor shall only Process Client Personal Data on behalf of Controller in accordance with this DPA and in accordance with Controller's instructions, unless Processing is required by Applicable Privacy Laws to which Processor is subject, in which case Processor shall, to the extent permitted by Applicable Privacy Law, inform and coordinate with Controller prior to Processing. B. Controller has authorized Counsel to issue instructions within the meaning of Section 3.1 to Processor on Controller's behalf. Processor may act upon instructions by Counsel as if directly received from Controller. Controller is responsible for ensuring that Counsel is appropriately authorized to validly issue instructions on the Processing of Client Personal Data on behalf of Controller to Processor. C. Processor shall not sell or disclose Client Personal Data to third parties other than as provided under this DPA. No copies or duplicates of Client Personal Data may be produced without the knowledge of Controller. This does not apply to the creation of backup copies to facilitate compliance with Applicable Privacy Laws. D. To the extent required by Applicable Privacy Laws, Processor shall maintain a record of all categories of Processing activities carried out on behalf of Controller, which shall be compliant with Applicable Privacy Laws.
IV. Notification Obligations
A. Processor shall immediately notify Controller of any monitoring activities and measures undertaken by a supervisory authority or other applicable regulatory body in respect of it, to the extent such monitoring activities and measures are made in connection with Client Personal Data. B. Processor shall immediately and in any event within 5 business days inform the Controller in the event that it receives a request from a Data Subject relating to the Client Personal Data. C. Processor shall notify Controller of a Personal Data Breach without undue delay of Processor becoming aware of the Personal Data Breach. In consultation with Controller, Processor shall take reasonable and appropriate measures in accordance with Applicable Privacy Laws and industry standards to secure Personal Data and limit possible detrimental effects to Data Subjects. Where obligations are placed on Controller under Applicable Privacy Laws, Processor must provide reasonable assistance to Controller in meeting such obligations.
V. Technical and Organizational Measures
Processor shall implement the technical and organizational measures set forth in Exhibit 2 (Technical and Organizational Measures). Processor shall maintain appropriate industry-standard technical and organizational measures for protection of Client Personal Data Processed hereunder (including measures against unauthorized or unlawful Processing and against accidental or unlawful destruction, loss or alteration or damage, unauthorized disclosure of, or access to, Client Personal Data, confidentiality, and integrity of Client Personal Data).
VI. Authorized Persons and Training
Processor shall ensure that only its designated authorized persons shall be provided access to Client’s Personal Data. Processor shall ensure that its designated authorized persons receive adequate training to ensure compliance with Processing requirements under this DPA and are subject to a confidentiality agreement or are under an appropriate statutory obligation of confidentiality.
VII. Compliance with Applicable Privacy Laws
Upon written reasonable request of Controller and taking into account the nature of Processing and information available, Processor shall assist Controller, at Controller’s cost, in ensuring compliance with the obligations pursuant to Applicable Privacy Laws, including but not limited to security of Processing, Personal Data Breach notification, data protection impact assessment, consultation with or requests of a competent data protection authority and inquiries about Controller’s Processing of Client Personal Data pursuant to this DPA. To the extent required and permitted under Applicable Privacy Laws Processor shall provide all available information to Controller to demonstrate compliance with personal data processing obligations under this DPA.
VIII. Audit Rights of Controller
Upon Controller’s prior written request at reasonable intervals (but no more than once every 12 months, with the exception of a Personal Data Breach by Processor, and in such event Controller may request an audit despite the current audit interval), and Processor shall make available to Controller that is not a competitor of Processor (or Controller’s independent, reputable, third-party auditor that is not a competitor of Processor and not in conflict with Processor) information necessary to demonstrate compliance with this DPA, and allow for and contribute to audits, including inspections, conducted by them. Processor may satisfy its obligations under this section by answering Controller’s questionnaire-based audits and/or by providing Controller with attestations, certifications and summaries of audit reports conducted by accredited third party auditors solely related to Processor’s compliance with this DPA. Any information relating to audits, inspections, and the results therefrom, including the documents reflecting the outcome thereof, shall only be used by Controller to assess Processor’s compliance with this DPA, and shall not be used for any other purpose or disclosed to any third party without Processor’s prior written approval. Upon Processor’s first request, Controller shall transfer to Processor all records or documentation that was provided by Processor or collected and/or generated by Controller (or each of its mandated auditors) in the context of the audit and/or the inspection.
IX. Data Subject Rights
Taking into consideration the nature of Client Personal Data Processing, Processor shall: 1. Not respond to the Data Subject request itself or by Subprocessor unless required by Applicable Privacy Laws. 2. Notify Controller without undue delay if Processor or any Subprocessor receives a request from a Data Subject under any Applicable Privacy Laws with respect to Client Personal Data. 3. Reasonably assist Controller through appropriate technical and organizational measures to fulfill Controller’s obligation to respond to Data Subject requests arising under Applicable Privacy Laws.
X. Deletion of Client Personal Data
A. Processing of Client Personal Data by Processor shall only take place for the duration specified in the Agreement, unless terminated earlier pursuant to the terms and conditions of the Agreement (“Processing Time Frame”); provided however, and only if applicable to the Controller, Processor preserves user data associated with a terminated or expired Wizer account for a period of ninety (90) days following the termination or expiration of such account subscription. In specific circumstances, Wizer may prolong the retention of certain user data when it is necessary: (i) by legal, regulatory, tax, or accounting requirements, (ii) for maintaining an accurate record of the user interactions with Wizer in case of complaints or challenges, if applicable; or (iii) if applicable, Wizer reasonably believes there is a potential for litigation related to such user data. B. Subject to the above said, at the end of the Processing Time Frame: 1. Client Personal Data will be deleted within ninety (90) days following the end of the Processing Time Frame, unless retention of Client Personal Data is required pursuant to Applicable Privacy Laws or the circumstances described above. 2. Upon Controller’s written request, Processor shall, at the choice of Controller: a. Return the Client Personal Data to Controller; or b. Delete the Client Personal Data and provide Controller with a written confirmation of deletion of the Client Personal Data.
XI. Subprocessors
A. Processor may engage Subprocessors to assist in providing the Services to the extent permitted under this Section XII. Processor shall maintain a list of Subprocessors that process Client Personal Data and shall provide a copy of such list to Controller upon request. As of the Effective Date, Controller hereby grants Processor general written authorization to engage with the Sub-processors set out at Exhibit 4 hereto, which are currently used by Processor to process Personal Data. B. Processor shall carry out adequate due diligence to ensure that the Subprocessor is capable of providing the level of protection for Client Personal Data required by Applicable Privacy Laws, this DPA and the Agreement. Processor shall enter into a written agreement with each Subprocessor, to the extent applicable to the nature of the Services provided by such Subprocessor, and shall impose on that Subprocessor the same data protection obligations as set out in this DPA between the Parties. Processor shall maintain copies of its agreements with Subprocessors and make such agreements available as Controller may request from time to time. To the extent necessary to protect confidential information, Processor may redact copies prior to sharing with Controller. C. To the extent a Subprocessor is established in a Third Country, Processor shall ensure that any onward transfer of Personal Data originally transferred pursuant to clause XIII(A) shall be made in compliance with the requirements of the Applicable Privacy Law and in particular, where required, that Processor (as data exporter) and the Subprocessor (as data importer) will enter into the applicable Standard Contractual Clauses. D. Processor shall be liable for the acts and omissions of its Subprocessors to the same extent Processor would be liable if performing the Services under the terms of this DPA. E. Processor shall provide Controller with written notice of newly appointed Subprocessors (including the jurisdiction in which each Subprocessor is established) before authorizing such Subprocessors to Process Client Personal Data in connection with providing the Services. Controller may object to Processor’s appointment of a new Subprocessor by providing written notice to Processor within fifteen (15) calendar days of receiving Processor’s notification. Such notice shall explain the reasonable grounds for the objection. In the event Controller objects to a new Subprocessor, Processor will use commercially reasonable efforts to make available to Controller a change in the Services or recommend a commercially reasonable change to Controller’s configuration or use of the Services to avoid the Processing of Client Personal Data by the objected-to new Subprocessor without unreasonably burdening Controller. If Processor is unable to make available such change within a reasonable period of time, which shall not exceed thirty (30) calendar days, either Party may terminate this DPA without penalty by providing written notice to the other Party.
XII. Restricted Transfers
A. To the extent that a Restricted Transfer of Client Personal Data is made: 1. To the extent that the Client Personal Data originated in the EEA and/or the Controller is established in the EEA, the EEA SCCs shall apply; 2. To the extent that the Client Personal Data originated in Switzerland and/or the Controller is established in Switzerland, the Swiss SCCs shall apply; and/or 3. To the extent that the Client Personal Data originated in the UK and/or the Controller is established in the UK, the UK SCCs shall apply. B. Where Clause XIII(A) of this DPA applies, the Parties agree to be bound by, observe, comply with and perform the applicable Standard Contractual Clauses as if the Standard Contractual Clauses were set out in, and incorporated into this DPA. Controller and Processor are deemed to have executed and signed the applicable Standard Contractual Clauses by entering into this DPA.
XIII. General Terms
A. Governing Law and Jurisdiction. The Parties to this DPA hereby submit to the choice of jurisdiction specified in the Agreement. B. Order of Precedence. In the event of any inconsistency between the provisions of this DPA and the provisions of the Agreement, the provisions of this DPA shall prevail solely with respect to the Processing of Client’s Personal Data. The EEA SCCs, UK SCCs and/or Swiss SCCs (as applicable) shall take precedence over the provisions of this DPA and the Agreement solely with respect to the Processing of Client’s Personal Data. C. Changes in Applicable Privacy Laws. In the event of any changes to Applicable Privacy Laws affecting the terms of this DPA, the Parties agree to negotiate in good faith the amendment of this DPA as applicable and necessary to comply with the changes in Applicable Privacy Laws. D. Severance. Should any provision of this DPA be deemed invalid or unenforceable by a court of competent jurisdiction, then the remainder of this DPA shall remain in full force and effect. The invalid or unenforceable provisions shall either be: (a) amended by the Parties as necessary to ensure validity and enforceability, while preserving the Parties’ intentions as closely as possible; or, if (a) is not feasible, construe such provision in a manner as if the invalid or unenforceable provision was not originally made a part of this DPA. E. Assignment of Rights and Delegation of Duties. Any assignment of rights or obligation hereunder by a Party hereto shall be made in accordance with the Agreement. F. Force Majeure. Non-performance of either Party will be excused to the extent performance is rendered impossible by strike, fire, war, flood, governmental acts or orders or restrictions, or act of God, or any other reason where failure to perform is beyond the reasonable control of the non-performing Party. G. Nature of DPA. Nothing in this DPA shall be construed to create (i) a partnership, joint venture or other joint business relationship between the Parties or any of their affiliates, (ii) any fiduciary duty owed by one Party to another Party or any of its affiliates, or (iii) a relationship of employer and employee between the Parties. H. No Waiver. Failure or delay on the part of either Party to exercise any right, power, privilege, or remedy hereunder shall not constitute a waiver thereof. No provision of this DPA may be waived by either Party except by a writing signed by an authorized representative of the Party making the waiver. I. No Third Party Beneficiaries. Save as otherwise provided by the EEA SCCs, UK SCCs and/or Swiss SCCs (as applicable) nothing in this DPA shall be considered or construed as conferring any right or benefit on a person not Party to this DPA nor imposing any obligations on either Party hereto to persons not a Party to this DPA. J. Term. The term of this DPA shall commence on the Effective Date and terminate concomitantly with the Agreement, unless terminated earlier in accordance with this Section XIV. K. Termination. Either Party may terminate this DPA immediately if the non-breaching Party determines, in its sole and reasonable discretion, that the other Party has breached a material term of this DPA and a cure is infeasible. Otherwise, the non-breaching Party shall provide the breaching Party with thirty (30) days from the breaching Party‘s receipt of a notice to cure such breach. If the breaching Party fails to cure such breach within thirty (30) days, then the non-breaching Party may terminate this DPA. L. Entire Agreement. The Parties acknowledge and agree that they have read, understood and accept this DPA, including any exhibits and attachments, and that this DPA constitutes the entire agreement between them as to the subject matter herein, and supersedes all other communications, written or oral, relating to the subject matter of this DPA.
Exhibit 1 - Description of Processing Activities
Nature and Purpose of Processing
1. Providing Services stipulated in the Agreement and/or other contracts executed by and between the Parties to Client. Processor’s processing activities on behalf of Controller typically relate to cyber risk management, incident prevention, incident management and/or incident response, unless otherwise stated in the Agreement and/or other contracts executed by and between the Parties.
2. Performing the Agreement, this DPA and/or other contracts executed by and between the Parties.
3. Acting upon Client’s instructions, where such instructions are consistent with the terms of the Agreement.
4. Sharing Client’s Personal Data with third parties in accordance with Client’s instructions and/or pursuant to Client’s use of the Services (e.g., integrations between the Services and any services provided by third parties, as configured by or on behalf of Client to facilitate the sharing of Client Personal Data between the Services and such third-party services).
5. Rendering Client Personal Data anonymized pursuant to Applicable Privacy Laws.
6. Complying with applicable laws and regulations.
7. All tasks related to any of the above. The processing for the above purposes may include the handling, collection, recording, organization, analysis, structuring, storage, adaptation or alteration, retrieval, consultation, use, editing, modifying, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, pseudonymization or anonymization, and/or destruction of Personal Data.
Duration of Processing
Subject to any section of the DPA and/or the Agreement dealing with the duration of the Processing and the consequences of the expiration or termination thereof, Processor will Process Client’s Personal Data for the duration of the Agreement and provision of the Services thereunder, unless otherwise agreed upon in writing; provided however that Vendor preserves user data associated with a terminated or expired Wizer account for a period of ninety (90) days following the termination or expiration of such account subscription (if use of Wizer is applicable to the specific Processor platform used by Controller). In specific circumstances, Processor may prolong the retention of certain user data when it is necessary: (i) by legal, regulatory, tax, or accounting requirements, (ii) for maintaining an accurate record of the user interactions with Wizer in case of complaints or challenges (if applicable), or (iii) if Wizer reasonably believes there is a potential for litigation related to such user data (if applicable).
Type of Personal Data
Subject to the provisions of the Agreement and this DPA, Controller may submit Personal Data to the Services, the type and extent of which is determined and controlled by Controller in its sole discretion. The Parties agree that the Services are not intended for the Processing of Sensitive Data, and that if Client wishes to use the Services to Process Sensitive Data, it must first obtain Wizer's explicit prior written consent and enter into any additional agreements as may be required by Wizer, if Wizer is applicable to the specific platform used by Controller. Types of Personal Data may include, but are not limited to, any of the following:
Contact and business profile data (such as name, business contact details, job title and company affiliation).
Account and user management data (such as account identifiers, user roles, access credentials and related administrative data).
Technical, device and usage data generated in connection with the provision and use of the Services (such as authentication logs, network flow data, vulnerability scan results, indicators of compromise).
Customer content and other information submitted to, stored on, or otherwise processed through the Services, as determined by Controller (such as personal data included in backup data sets, communication (e.g., email) contents and metadata, records potentially assessed in the context of an incident, as may be applicable to the Services.
Categories of Data Subjects
The Categories of Data Subjects relating to the Client Personal Data that will be processed by Processor are dependent on Controller, and may include, but are not limited to, any of the following categories:
Employees, agents, advisors, freelancers of Client (who are natural persons).
Prospects, customers, business partners and vendors of Client (who are natural persons).
Any other third-party individual whose Personal Data is Processed by the Services.
Exhibit 2: Technical & Organizational Measures
1. General Considerations This Exhibit 2 details the technical and organizational measures (“TOMs”) that the Processor is required to implement and maintain to ensure the secure and compliant processing of personal data. These TOMs are designed to uphold the rights of data subjects and fulfill the mandates of the GDPR, , including Articles 24, 25, and 32.
2. Organization Processor has appointed a dedicated Data Protection Officer (DPO) tasked with overseeing compliance with Applicable Privacy Laws, including GDPR. The DPO's responsibilities specifically include, but are not limited to:
Monitoring & Advice: Monitoring compliance with Applicable Privacy Laws, providing regular counsel on data protection obligations, and advising on Data Protection Impact Assessments (DPIAs).
TOMs Review: Conducting at least an annual review of these TOMs to ensure effectiveness against evolving security threats and changes in privacy legislation.
Incident Response: Acting as a core member of the Incident Response Team to ensure that data breaches are documented and communicated to the Controller without undue delay.
Point of Contact: Serving as the designated contact point for data subjects, the Controller, and supervisory authorities regarding the processing of personal data under this Agreement. The DPO may be reached at privacy@coalitioninc.com.
3. Confidentiality 3.1 Physical Access Control Processor shall maintain and enforce a physical security policy which governs physical security controls for both remote work and office requirements. These restrictions include 15-minute session locks on endpoints, clean desk requirements, identification requirements for physical offices, and VPN for remote workers. 3.2 Access and Usage Control The Processor shall implement and maintain the following technical and organizational measures to protect personal data:
Access Control & Verification: Restrict personal data access strictly to authorized personnel and implement automated mechanisms to verify access to all systems containing personal data.
Identity & Access Management:
Enforce Role-Based Access Controls (RBAC) and the Principle of Least Privilege to ensure personnel only access data strictly necessary for their specific tasks.
Adhere to Data Minimization and Purpose Limitation principles for all data processing activities.
Authentication & Passwords: Enforce strict password policies across all applications storing personal data, which include mandatory multi-factor authentication (MFA/2FA).
Monitoring & Logging: Continuously monitor and log all system access, including tracking both successful and unsuccessful login attempts.
Regular Audits: Conduct a formal review of all user access privileges to personal data at least annually to ensure ongoing compliance and necessity.
3.3 Encryption
In accordance with Article 32 of the GDPR, the Processor shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including the pseudonymization and encryption of personal data as detailed below:
Data Encryption in Transit and at Rest: The Processor shall encrypt all personal data, both during transmission in transit and at rest.
Cryptographic Standards & Backups: Encryption must utilize state-of-the-art cryptographic algorithms, establishing a minimum standard of AES-256 (or equivalent industry-recognized strong encryption). This requirement strictly extends to all backup data, archives, and disaster recovery repositories.
Endpoint Security: The Processor shall enforce full-disk or storage-level encryption on all endpoints (including laptops, mobile devices, and workstations) capable of accessing personal data. Access to these endpoints must be secured by strong authentication mechanisms before any personal data can be decrypted or accessed.
3.4 Anonymization Where processing requires the de-identification of datasets, Processor shall apply rigorous pseudonymization techniques, including aggregation in combination with k-anonymity, suppression or noise addition.
4. Integrity and Availability Processor shall implement and maintain sufficient and appropriate (based on the type of personal data exported and its sensitivity) environmental, physical and logical security measures with respect to personal data and to Processor’s system infrastructure. This includes but is not limited to the following: 4.1 System Resilience and Vulnerability Management:
Infrastructure Patch Management: Processor shall process personal data exclusively on infrastructure subject to documented, proactive patch management protocols. This ensures systems are resilient against exploitation that could compromise data integrity or cause system downtime.
Vulnerability Detection: Processor shall conduct automated vulnerability scanning across all endpoints and data processing environments at least quarterly.
Independent Security Assessments: Processor shall perform comprehensive risk assessments and independent, third-party penetration testing at least annually. The Processor shall execute a formalized remediation plan to fix identified vulnerabilities according to their severity to prevent unauthorized modification or disruption of services.
Continuity Reviews: Processor shall establish a regular process to review technical advancements, ensuring that system protections scale dynamically against evolving threats to data availability.
4.2 Endpoint Security and Device Integrity Processor shall enforce strict security standards on all devices with access to personal data to prevent malware from compromising data integrity. Devices must feature mandatory anti-malware software, secure passcode authentication, supported operating systems and full-disk storage encryption.
4.3 Cryptographic Protections
To prevent unauthorized alterations and eavesdropping, personal data must be encrypted based on data classification both in transit and at rest using minimum AES-256 or equivalent industry-recognized strong cryptographic standards.
4.4 Backup Architecture and Disaster Recovery
Processor shall maintain redundant storage media and isolated backups in line with modern technical standards. All critical processing systems must utilize immutable backup architectures to protect archives against ransomware and unauthorized deletion.
Processor shall maintain, update and test comprehensive business continuity and disaster recovery (BCDR) plans annually. These plans must be designed to restore the availability of, and access to, personal data in a timely and accurate manner following a physical or technical incident.
4.5 Operational Governance
Processor shall maintain 24/7/365 security alert monitoring and facility security for all environments hosting personal data to detect and mitigate availability threats or unauthorized access in real time.
Processor shall maintain an accurate inventory of personal data along with specific disposal instructions, adhering strictly to established document retention and destruction policies to prevent accidental data loss or improper premature deletion.
Processor shall test security and privacy controls for operational effectiveness annually, utilizing continuous monitoring where possible.
4.6 Incident Handling, Breach Management and Data Subject Rights
Processor shall maintain a documented incident response framework to minimize damage from security incidents. This includes the automated collection and secure retention of forensic event logs to track data integrity anomalies.
Processor shall structure incident procedures to notify the Controller without undue delay following a data breach, ensuring the Controller can meet its statutory 72 hour notification mandate under GDPR.
Processor shall provide technical and operational workflows to assist the Controller in fulfilling data subject rights, including the right to erasure.
5. Data Protection by Design and Default In accordance with Article 25 GDPR, the Processor shall implement appropriate technical and organizational measures both at the time of the determination of the means for processing and at the time of processing itself: 5.1 Data Protection by Design: The Processor shall embed Data Protection by Design principles into all systems, applications, infrastructure, and feature enhancements at the earliest state of development. Development workflows must proactively integrate safeguards to protect data subjects’ rights and ensure processing adheres to GDPR principles. 5.2 Data Protection by Default: The Processor shall implement mechanisms ensuring that, by default, only personal data necessary for each specific purpose of the processing is processed. This applies to the amount of personal data collected, the extent of processing, the retention period and accessibility. 5.3 In executing these principles, the Processor’s development lifecycle will account for:
The state of the art and implementation costs.
The nature, scope, context, and purposes of the processing.
The anonymization and minimization of personal data wherever feasible.
Ensuring that personal data is not made accessible to the indefinite number of natural persons without human intervention.
6. Personnel Security and Awareness The Processor shall ensure that access to personal data is strictly limited to authorized personnel who have a legitimate business need to access such data. In relation to such personnel, the Processor shall implement the following measures:
The Processor shall ensure that all employees, agents, and subcontractors authorized to process personal data have executed legally binding confidentiality agreements during the onboarding process, or are under appropriate statutory obligations of confidentiality. This obligation shall survive the termination of their employment or engagement, as applicable.
The Processor shall require all personnel with access to personal data to complete mandatory data protection, privacy, and security awareness training annually. Training will cover GDPR compliance - including but not limited to data subject rights and data breach reporting procedures.
As a condition of employment or engagement, and to the extent permitted under applicable laws, the Processor shall conduct appropriate background checks for screening to verify the reliability of any personnel who have access to personal data.
Exhibit 3 – Controller Sub-Processors
The Controller has authorised the use of the following sub-processors:
Subprocessor | Use Case | Processing Location |
AgentSync, Inc. | Management of broker and agent information. | United States |
Amazon Web Services, Inc. | Hosting and storage systems provider. | United States |
Argus West, Inc. | Compliance training platform. | United States |
Catamorphic, Co. d/b/a LaunchDarkly | Development feature flagging and platform management. | United States |
Centiment LLC | Conducts surveys for targeted audiences, including Coalition clients. | United States |
Chameleon.io | Platform that enables the building of product experiences, walk-throughs, tooltips and announcements to improve UX. | United States |
Channelscaler | Client engagement and ecosystem growth platform. | United States |
Chili Piper, Inc. | Scheduling application for engagement with brokers. | United States |
Clickhouse, Inc. | Hosting and storage systems provider | United States |
Contentful GmbH | Web hosting for various sites. | Germany |
ECE Consulting Group, Inc. a/k/a ECE Contact Centers, Inc. | Customer service, technical support and data entry. | Philippines |
eWebinar Labs | Webinar platform for hosting external broker platforms. | United States |
Experian Information Solutions, Inc. | Data factor (credit score) for issuing quotes. | United States |
Github Inc. | Cloud-based service for software development. | United States |
Gong.io Ltd | Intelligence platform capturing conversations for the purpose of analysis. | United States |
Google LLC | G Suite, Google Analytics, LLM hosting and Looker. | United States |
Hubspot, Inc. | CRM, client management. | United States |
IDB, LLC | IP address enrichment | United States |
Intercom | Support and user guides | Dependent on client configuration |
Ironclad, Inc. | Contract management and storage. | United States |
Lob.com, Inc. | Direct mail SaaS platform. | United States |
Loom, Inc. | Platform for creating training content and videos. | United States |
Marketo, Inc. | Marketing automation software. | United States |
Mentimeter AB | Real-time polls for slide decks. | Sweden |
Microsoft Azure | Hosting and storage systems provider | Dependent on client location |
Netsuite Inc. | Accounting and leads software. | United States |
Okta, Inc. | Authentication/SSO application. | United States |
OneTrust, LLC | Website cookie banner. | United States |
OpenAI | AI application. | United States |
Outreach Corporation | Sales engagement. | United States |
Pandadoc Inc. | Document signing application. | United States |
Rocket Science Group, LLC d/b/a Mailchimp | Email platform used to communicate with brokers and policyholders. | United States |
Salesforce, Inc. | CRM | United States |
SentinelOne, Inc. | Endpoint detection response tool for investigations and managing clients. | United States |
ShareFile, LLC | Secure file sharing. | United States |
Slack Technologies, Inc. | Internal messaging; external with consent. | United States |
Snowflake Inc. | Cloud-based database. | United States |
Stripe, Inc. | Payment collection used for subscription plans. | United States |
Superlative Enterprises Pty Ltd | Threat and exposure intelligence | Australia |
Sutro Labs, Inc. | Reverse ETL tool, moves data from warehouse to Salesforce CRM. | United States, Germany |
Twilio, Inc. | Sales outreach. | United States |
Vertafore, Inc. | Agency management software. | United States |
WeWork | Flexible office and coworking spaces. | United States, Canada, Germany, UK, Australia |
Wizer Inc. | Information Security training partner. | United States |
In addition to the subprocessors listed above, the following entities are part of the Coalition group, and accordingly may also function as subprocessors in order to provide Coalition’s products and services:
Entity Name | Processing Location |
Coalition Insurance Solutions AG | Switzerland |
Coalition - Deiniram Doluções de Segurança, Unipessoal, Lda. | Portugal |
Coalition Incident Response, Inc. | United States |
Coalition Insurance Solutions GmbH | Germany |
Coalition Insurance Solutions, Inc. | United States |
Coalition Insurance Solutions Pty Ltd. | Australia |
Coalition Risk Solutions Ltd. | United Kingdom |