Common use of Subprocessing Clause in Contracts

Subprocessing. 5.1 Customer authorises SentinelOne to appoint (and permit each Subprocessor appointed in accordance with this section 5 to appoint) Subprocessors in accordance with this section 5 and any restrictions in the Agreement. SentinelOne shall make available to Customer the current list of Subprocessors that are processing Customer Personal Data, attached as Annex 3. SentinelOne shall provide Customer prior written notice of the appointment of any new Subprocessor, including details of the Processing to be undertaken by the Subprocessor. If, within thirty (30) days of receipt of that notice, Customer notifies SentinelOne in writing of any objections to the proposed appointment, and further provides commercially reasonable justifications to such objections based on valid concerns regarding such proposed Subprocessor’s business practices relating to data protection, then (i) SentinelOne shall work with Customer in good faith to address Customer’s objections regarding the new Subprocessor; and (ii) where Customer’s concerns cannot be resolved within thirty (30) days from SentinelOne's receipt of Customer's notice, notwithstanding anything in the Agreement, Customer may, by providing SentinelOne with a written notice to with immediate effect, terminate the Agreement and SentinelOne shall refund to Customer all prepaid Fees for the Solutions attributable to the Subscription Term (as outlined in the applicable Purchase Order) following the termination of these Terms. 5.2 With respect to each Subprocessor, SentinelOne shall: 5.2.1 before the Subprocessor first Processes Customer Personal Data, carry out adequate due diligence to ensure that the Subprocessor is capable of providing the level of protection for Customer Personal Data required by the Agreement; 5.2.2 ensure that the arrangement between on the one hand (a) SentinelOne, or (b) the relevant intermediate Subprocessor; and on the other hand, the Subprocessor, is governed by a written contract including terms which offer at least the same level of protection for Customer Personal Data as those set out in this Addendum and meet the requirements of Article 28(3) of the GDPR; 5.2.3 if that arrangement involves a Restricted Transfer, ensure that the Standard Contractual Clauses are at all relevant times incorporated into the agreement between on the one hand (a) SentinelOne, or (b) the relevant intermediate Subprocessor; and on the other hand the Subprocessor, or before the Subprocessor first Processes Customer Personal Data procure that it enters into an agreement incorporating the Standard Contractual Clauses with the Customer. and 5.2.4 provide to Customer for review such copies of the Contracted Processors' agreements with Subprocessors (which may be redacted to remove confidential commercial information not relevant to the requirements of this Addendum) as Customer may request from time to time. 5.3 SentinelOne shall ensure that each Subprocessor performs its obligations under sections 2.1, 3, 4, 6.1, 7.2, 8 and 10.1, as they apply to Processing of Customer Personal Data carried out by that Subprocessor, as if it were party to this Addendum in place of SentinelOne.

Appears in 3 contracts

Sources: Data Protection Addendum, Data Protection Addendum, Data Protection Addendum

Subprocessing. 5.1 6.1 Each Customer Group Member authorises SentinelOne JourneyApps and each JourneyApps Affiliate to appoint (and permit each Subprocessor appointed in accordance with this section 5 6 to appoint) Subprocessors in accordance with this section 5 6 and any restrictions in the Principal Agreement. SentinelOne . 6.2 JourneyApps and each JourneyApps Affiliate may continue to use those Subprocessors already engaged by JourneyApps or any JourneyApps Affiliate as at the date of this DPA, subject to JourneyApps and each JourneyApps Affiliate in each case as soon as practicable meeting the obligations set out in section 6.4. 6.3 JourneyApps shall make available to Customer the current list of Subprocessors that are processing Customer Personal Data, attached as Annex 3. SentinelOne shall provide give Customer prior written notice of the appointment of any new Subprocessor, including full details of the Processing to be undertaken by the Subprocessor. If, within thirty sixty (3060) days of receipt of that notice, Customer notifies SentinelOne JourneyApps in writing of any objections (on reasonable grounds) to the proposed appointment, and further provides commercially neither JourneyApps nor any JourneyApps Affiliate shall appoint (or disclose any Customer Personal Data to) that proposed Subprocessor until reasonable justifications to such objections based on valid concerns regarding such proposed Subprocessor’s business practices relating to data protection, then (i) SentinelOne shall work with Customer in good faith steps have been taken to address Customer’s the objections regarding the new Subprocessor; raised by any Customer Group Member and (ii) where Customer’s concerns cannot be resolved within thirty (30) days from SentinelOne's receipt of Customer's notice, notwithstanding anything in the Agreement, Customer may, by providing SentinelOne has been provided with a reasonable written notice to with immediate effect, terminate explanation of the Agreement and SentinelOne shall refund to Customer all prepaid Fees for the Solutions attributable to the Subscription Term (as outlined in the applicable Purchase Order) following the termination of these Termssteps taken. 5.2 6.4 With respect to each Subprocessor, SentinelOne JourneyApps or the relevant JourneyApps Affiliate shall: 5.2.1 6.4.1 before the Subprocessor first Processes Customer Personal DataData (or, where relevant, in accordance with section 6.2), carry out adequate due diligence to ensure that the Subprocessor is capable of providing the level of protection for Customer Personal Data required by the Principal Agreement; 5.2.2 6.4.2 ensure that the arrangement between on the one hand (a) SentinelOneJourneyApps, or (b) the relevant JourneyApps Affiliate, or (c) the relevant intermediate Subprocessor; and on the other hand, hand the Subprocessor, is governed by a written contract including terms which offer at least the same level of protection for Customer Personal Data as those set out in this Addendum DPA and meet the requirements of Article article 28(3) of the GDPR; 5.2.3 6.4.3 if that arrangement involves a Restricted Transfer, ensure that the Standard Contractual Clauses are at all relevant times incorporated into the agreement between on the one hand hand (a) SentinelOneJourneyApps, or (b) the relevant JourneyApps Affiliate, or (c) the relevant intermediate Subprocessor; and on the other hand the Subprocessor, or before the Subprocessor first Processes Customer Personal Data procure that it enters into an agreement incorporating the Standard Contractual Clauses with the Customer. relevant Customer Group Member(s) (and Customer shall procure that each Customer Affiliate party to any such Standard Contractual Clauses co-operates with their population and execution); and 5.2.4 6.4.4 provide to Customer for review such copies of the Contracted Processors' agreements with Subprocessors (which may be redacted to remove confidential commercial information not relevant to the requirements of this AddendumDPA) as Customer may request from time to time. 5.3 SentinelOne 6.5 JourneyApps and each JourneyApps Affiliate shall ensure that each Subprocessor performs its the obligations under sections 2.1, 33.1, 4, 6.15, 7.27.1, 8 8.2, 9 and 10.111.1, as they apply to Processing of Customer Personal Data carried out by that Subprocessor, as if it were party to this Addendum DPA in place of SentinelOneJourneyApps.

Appears in 3 contracts

Sources: Data Processing Addendum, Data Processing Addendum, Data Processing Addendum

Subprocessing. 5.1 Customer authorises SentinelOne to appoint (and permit each Subprocessor appointed in accordance with this section 5 to appoint) Subprocessors in accordance with this section 5 and any restrictions in the Agreement. SentinelOne shall make available to Customer the current list of Subprocessors that are processing Customer Personal Data, attached as Annex 3. SentinelOne shall provide Customer prior written notice of the appointment of any new Subprocessor, including details of the Processing to be undertaken by the Subprocessor. If, within thirty (30) days of receipt of that notice, Customer notifies SentinelOne in writing of any objections to the proposed appointment, and further provides commercially reasonable justifications to such objections based on valid concerns regarding such proposed Subprocessor’s business practices relating to data protection, then (i) SentinelOne shall work with Customer in good faith to address Customer’s objections regarding the new Subprocessor; and (ii) where Customer’s concerns cannot be resolved within thirty (30) days from SentinelOne's receipt of Customer's notice, notwithstanding anything in the Agreement, Customer may, by providing SentinelOne with a written notice to with immediate effect, terminate the Agreement and SentinelOne shall refund to Customer all prepaid Fees for the Solutions attributable to the Subscription Term (as outlined in the applicable Purchase Order) following the termination of these Termsthe Agreement. 5.2 With respect to each Subprocessor, SentinelOne shall: 5.2.1 before the Subprocessor first Processes Customer Personal Data, carry out adequate due diligence to ensure that the Subprocessor is capable of providing the level of protection for Customer Personal Data required by the Agreement; 5.2.2 ensure that the arrangement between on the one hand (a) SentinelOne, or (b) the relevant intermediate Subprocessor; and on the other hand, the Subprocessor, is governed by a written contract including terms which offer at least the same level of protection for Customer Personal Data as those set out in this Addendum and meet the requirements of Article 28(3) of the GDPR; 5.2.3 if that arrangement involves a Restricted Transfer, ensure that the Standard Contractual Clauses are at all relevant times incorporated into the agreement between on the one hand (a) SentinelOne, or (b) the relevant intermediate Subprocessor; and on the other hand the Subprocessor, or before the Subprocessor first Processes Customer Personal Data procure that it enters into an agreement incorporating the Standard Contractual Clauses with the Customer. and 5.2.4 provide to Customer for review such copies of the Contracted Processors' agreements with Subprocessors (which may be redacted to remove confidential commercial information not relevant to the requirements of this Addendum) as Customer may request from time to time. 5.3 SentinelOne shall ensure that each Subprocessor performs its obligations under sections 2.1, 3, 4, 6.1, 7.2, 8 and 10.1, as they apply to Processing of Customer Personal Data carried out by that Subprocessor, as if it were party to this Addendum in place of SentinelOne.

Appears in 3 contracts

Sources: Data Protection Addendum, Data Protection Addendum, Data Protection Addendum

Subprocessing. 5.1 Customer authorises SentinelOne to appoint Simplesat may engage Subprocessors in connection with the provision of the Service, provided that: (and permit 1) Simplesat has entered into a written agreement with each Subprocessor appointed containing data protection obligations not less protective than those in this Addendum with respect to the protection of Customer Personal Data to the extent applicable to the nature of the Service provided by such Subprocessor; and (2) Simplesat shall be liable for the acts and omissions of its Subprocessors to the same extent Simplesat would be liable if performing the Service of each Subprocessor directly under the terms of this Addendum. Simplesat’s current list of Subprocessors for the Service is available at ▇▇▇.▇▇▇▇▇▇▇▇▇.▇▇/▇▇▇▇▇▇▇▇▇▇▇▇▇ (“Subprocessor List”), which Customer hereby approves and authorizes. Simplesat may engage additional Subprocessors as Simplesat considers reasonably appropriate for the processing of Customer Personal Data in accordance with this section 5 Addendum, provided that Simplesat shall notify Customer of the addition or replacement of Subprocessors through a mechanism, accessible within the Subprocessor List, by which Customer may subscribe to appoint) notifications of new Subprocessors (the “Subprocessor Notification Mechanism”). If Customer does not subscribe to receive notifications through the Subprocessor Notification Mechanism, Customer shall be deemed to have waived its right to receive notification of new Subprocessors and Customer shall be responsible for periodically checking the Subprocessor List to remain informed of Simplesat’s current list of Subprocessors. Customer may, on reasonable grounds, object to a new Subprocessor by notifying Simplesat in accordance with this section 5 and any restrictions in writing within 10 days of Simplesat updating the AgreementSubprocessor List, giving reasons for Customer's objection. SentinelOne Customer’s failure to object within such 10-day period shall be deemed Customer’s waiver of its right to object to Simplesat’s use of such new Subprocessor added to the Subprocessor List. In the event Customer objects to a new Subprocessor, Simplesat will use reasonable efforts to make available to Customer a change in the current list of Subprocessors that are processing Customer Personal Data, attached as Annex 3. SentinelOne shall provide Customer prior written notice Service or recommend a commercially reasonable change to Customer’s configuration or use of the appointment of any new Subprocessor, including details of the Processing Service to be undertaken by the Subprocessor. If, within thirty (30) days of receipt of that notice, Customer notifies SentinelOne in writing of any objections to the proposed appointment, and further provides commercially reasonable justifications to such objections based on valid concerns regarding such proposed Subprocessor’s business practices relating to data protection, then (i) SentinelOne shall work with Customer in good faith to address Customer’s objections regarding the new Subprocessor; and (ii) where Customer’s concerns cannot be resolved within thirty (30) days from SentinelOne's receipt of Customer's notice, notwithstanding anything in the Agreement, Customer may, by providing SentinelOne with a written notice to with immediate effect, terminate the Agreement and SentinelOne shall refund to Customer all prepaid Fees for the Solutions attributable to the Subscription Term (as outlined in the applicable Purchase Order) following the termination of these Terms. 5.2 With respect to each Subprocessor, SentinelOne shall: 5.2.1 before the Subprocessor first Processes Customer Personal Data, carry out adequate due diligence to ensure that the Subprocessor is capable of providing the level of protection for Customer Personal Data required by the Agreement; 5.2.2 ensure that the arrangement between on the one hand (a) SentinelOne, or (b) the relevant intermediate Subprocessor; and on the other hand, the Subprocessor, is governed by a written contract including terms which offer at least the same level of protection for Customer Personal Data as those set out in this Addendum and meet the requirements of Article 28(3) of the GDPR; 5.2.3 if that arrangement involves a Restricted Transfer, ensure that the Standard Contractual Clauses are at all relevant times incorporated into the agreement between on the one hand (a) SentinelOne, or (b) the relevant intermediate Subprocessor; and on the other hand the Subprocessor, or before the Subprocessor first Processes Customer Personal Data procure that it enters into an agreement incorporating the Standard Contractual Clauses with the Customer. and 5.2.4 provide to Customer for review such copies of the Contracted Processors' agreements with Subprocessors (which may be redacted to remove confidential commercial information not relevant to the requirements of this Addendum) as Customer may request from time to time. 5.3 SentinelOne shall ensure that each Subprocessor performs its obligations under sections 2.1, 3, 4, 6.1, 7.2, 8 and 10.1, as they apply to avoid Processing of Customer Personal Data carried out by that Subprocessorthe objected to new Subprocessor without unreasonably burdening Customer. If Simplesat is unable to make available such change within a reasonable period of time, which shall not exceed 30 days, Customer may terminate, as if it were party Customer’s sole and exclusive remedy, the portion of the Agreement with respect only to this Addendum in place the Service (or portion thereof) which cannot be provided by Simplesat without the use of SentinelOnethe objected to new Subprocessor by providing written notice to Simplesat.

Appears in 2 contracts

Sources: Data Processing Addendum, Data Processing Addendum

Subprocessing. 5.1 Customer authorises SentinelOne 6.1. Each User Group Member authorizes Company and each Company Affiliate to appoint (and permit each Subprocessor appointed in accordance with this section 5 6 to appoint) Subprocessors in accordance with this section 5 6 and any restrictions in the AgreementDPA. 6.2. SentinelOne Company and each Company Affiliate may continue to use those Subprocessors already engaged by Company or any Company Affiliate as at the date of this Addendum, subject to Company and each Company Affiliate in each case as soon as practicable meeting the obligations set out in section 6.4. 6.3. Company shall make available to Customer the current list of Subprocessors that are processing Customer Personal Data, attached as Annex 3. SentinelOne shall provide Customer give User prior written notice of the appointment of any new Subprocessor, including full details of the Processing to be undertaken by the Subprocessor. If, within thirty (30) days [ ] of receipt of that notice, Customer User notifies SentinelOne Company in writing of any objections (on reasonable grounds) to the proposed appointment, and further provides commercially reasonable justifications to such objections based on valid concerns regarding such proposed Subprocessor’s business practices relating to data protection, then (i) SentinelOne : 6.3.1. Company shall work with Customer User in good faith to address Customer’s objections regarding make available a commercially reasonable change in the new provision of the Services which avoids the use of that proposed Subprocessor; and (ii) and 6.3.2. where Customer’s concerns such a change cannot be resolved made within thirty (30) 30 days from SentinelOneCompany's receipt of CustomerUser's notice, notwithstanding anything in the AgreementDPA, Customer may, User may by providing SentinelOne with a written notice to Company with immediate effect, effect terminate the Agreement and SentinelOne shall refund to Customer all prepaid Fees for the Solutions attributable DPA to the Subscription Term (as outlined in extent that it relates to the applicable Purchase Order) following Services which require the termination use of these Termsthe proposed Subprocessor. 5.2 6.4. With respect to each Subprocessor, SentinelOne Company or the relevant Company Affiliate shall: 5.2.1 6.4.1. before the Subprocessor first Processes Customer User Personal DataData (or, where relevant, in accordance with section 6.2), carry out adequate due diligence to ensure that the Subprocessor is capable of providing the level of protection for Customer User Personal Data required by the AgreementDPA; 5.2.2 6.4.2. ensure that the arrangement between on the one hand (a) SentinelOneCompany, or (b) the relevant Company Affiliate, or (c) the relevant intermediate Subprocessor; and on the other hand, hand the Subprocessor, is governed by a written contract including terms which offer at least the same level of protection for Customer User Personal Data as those set out in this Addendum and meet the requirements of Article article 28(3) of the GDPR; 5.2.3 6.4.3. if that arrangement involves a Restricted Transfer, ensure that the Standard Contractual Clauses are at all relevant times incorporated into the agreement between on the one hand hand (a) SentinelOneCompany, or (b) the relevant Company Affiliate, or (c) the relevant intermediate Subprocessor; and on the other hand the Subprocessor, or before the Subprocessor first Processes Customer User Personal Data procure that it enters into an agreement incorporating the Standard Contractual Clauses with the Customer. relevant User Group Member(s) (and User shall procure that each User Affiliate party to any such Standard Contractual Clauses co-operates with their population and execution); and 5.2.4 6.4.4. provide to Customer User for review such copies of the Contracted Processors' agreements with Subprocessors (which may be redacted to remove confidential commercial information not relevant to the requirements of this Addendum) as Customer User may request from time to time. 5.3 SentinelOne 6.5. Company and each Company Affiliate shall ensure that each Subprocessor performs its the obligations under sections 2.1, 33.1, 4, 6.15, 7.27.1, 8 8.2, 9 and 10.111.1, as they apply to Processing of Customer User Personal Data carried out by that Subprocessor, as if it were party to this Addendum in place of SentinelOneCompany.

Appears in 2 contracts

Sources: Data Protection Addendum, Data Protection Addendum

Subprocessing. 5.1 Customer 6.1 Each Subscriber Group Member authorises SentinelOne eMudhra and each eMudhra Affiliate to appoint (,and permit each Subprocessor appointed in accordance with this section 5 6 to appoint) , Subprocessors in accordance with this section 5 6 and any restrictions in the Principal Agreement. SentinelOne . 6.2 eMudhra and each eMudhra Affiliate may continue to use those Subprocessors already engaged by eMudhra or any eMudhra Affiliate as at the date of this Addendum, subject to eMudhra and each eMudhra Affiliate in each case as soon as practicable meeting the obligations set out in section 6.4. 6.3 eMudhra shall make available to Customer the current list of Subprocessors that are processing Customer Personal Data, attached as Annex 3. SentinelOne shall provide Customer prior give Subscriber written notice or make publicly available on its website of the appointment of any new SubprocessorSubprocessor that will process Subscriber’s data, including details of the Processing to be undertaken by the Subprocessor. If, within thirty (30) 7 days of receipt of that notice, Customer Subscriber notifies SentinelOne eMudhra in writing of any objections (on reasonable grounds) to the proposed appointment, and further provides commercially : Neither eMudhra nor any eMudhra Affiliate shall appoint (or disclose any Subscriber Personal Data to) that proposed Subprocessor until reasonable justifications to such objections based on valid concerns regarding such proposed Subprocessor’s business practices relating to data protection, then (i) SentinelOne shall work with Customer in good faith steps have been taken to address Customer’s the objections regarding the new Subprocessor; raised by any Subscriber Group Member and (ii) where Customer’s concerns cannot be resolved within thirty (30) days from SentinelOne's receipt of Customer's notice, notwithstanding anything in the Agreement, Customer may, by providing SentinelOne Subscriber has been provided with a reasonable written notice to with immediate effect, terminate explanation of the Agreement and SentinelOne shall refund to Customer all prepaid Fees for the Solutions attributable to the Subscription Term (as outlined in the applicable Purchase Order) following the termination of these Terms.steps taken 5.2 6.4 With respect to each Subprocessor, SentinelOne eMudhra or the relevant eMudhra Affiliate shall: 5.2.1 6.4.1 before the Subprocessor first Processes Customer Subscriber Personal DataData (or, where relevant, in accordance with section 6.2), carry out adequate due diligence to ensure that the Subprocessor is capable of providing the level of protection for Customer Subscriber Personal Data required by the Principal Agreement; 5.2.2 6.4.2 ensure that the arrangement between on the one hand (a) SentinelOneeMudhra, or (b) the relevant eMudhra Affiliate, or (c) the relevant intermediate Subprocessor; and on the other hand, hand the Subprocessor, is governed by a written contract including terms which offer at least the same level of protection for Customer Subscriber Personal Data as those set out in this Addendum and meet the requirements of Article article 28(3) of the GDPR; 5.2.3 6.4.3 if that arrangement involves a Restricted Transfer, ensure that the Standard Contractual Clauses are at all relevant times incorporated into the agreement between on the one hand hand (a) SentinelOneeMudhra, or (b) the relevant intermediate Subprocessor; and on the other hand the SubprocessoreMudhra Affiliate, or before the Subprocessor first Processes Customer Personal Data procure that it enters into an agreement incorporating the Standard Contractual Clauses with the Customer. and 5.2.4 provide to Customer for review such copies of the Contracted Processors' agreements with Subprocessors (which may be redacted to remove confidential commercial information not relevant to the requirements of this Addendum) as Customer may request from time to time. 5.3 SentinelOne shall ensure that each Subprocessor performs its obligations under sections 2.1, 3, 4, 6.1, 7.2, 8 and 10.1, as they apply to Processing of Customer Personal Data carried out by that Subprocessor, as if it were party to this Addendum in place of SentinelOne.or

Appears in 2 contracts

Sources: Data Processing Addendum, Data Processing Addendum

Subprocessing. 5.1 4.1 Customer authorises specifically authorizes SentinelOne to appoint engage as Subprocessors those entities listed as of the effective date of this DPA at the URL specified in Section 4.2. In addition, and without prejudice to Section 4.4, Customer generally authorizes the engagement as Subprocessors of any other third parties (“New Subprocessors”). 4.2 Information about Subprocessors, including their functions and permit each Subprocessor appointed locations, is available at: ▇▇▇.▇▇▇▇▇▇▇▇▇▇▇.▇▇▇/▇▇▇▇▇/▇▇▇▇▇▇▇▇▇▇▇-▇▇▇-▇▇▇▇▇▇▇▇▇▇ (as may be updated by SentinelOne from time to time in accordance with this section 5 to appoint) Subprocessors DPA). 4.3 When any New Subprocessor is engaged while this DPA is in accordance with this section 5 and any restrictions in the Agreement. SentinelOne shall make available to Customer the current list of Subprocessors that are processing Customer Personal Dataeffect, attached as Annex 3. SentinelOne shall provide Customer at least thirty days’ prior written notice of the appointment engagement of any new New Subprocessor, including details of the Processing processing to be undertaken by the New Subprocessor. If, within thirty (30) days of receipt of that notice, Customer notifies SentinelOne in writing of any objections to the proposed appointment, and further provides commercially reasonable justifications to such objections based on valid concerns regarding such proposed that New Subprocessor’s business practices relating inability to data protectionadequately safeguard Customer Data, then (i) SentinelOne shall work with Customer in good faith to address Customer’s objections regarding the new New Subprocessor; and (ii) where Customer’s concerns cannot be resolved within thirty (30) days from SentinelOne's ’s receipt of Customer's ’s notice, notwithstanding anything in the Agreement, Customer may, by providing SentinelOne with a written notice to with immediate effect, terminate the Agreement and SentinelOne shall refund to Customer all prepaid Fees fees for the Solutions attributable to the Subscription Term subscription term (as outlined in the applicable Purchase OrderOrder under the Agreement) following the termination of these Termsthe Agreement. 5.2 4.4 With respect to each Subprocessor, SentinelOne shall: 5.2.1 4.4.1. before the Subprocessor first Processes processes Customer Personal Data, carry out adequate due diligence to ensure that the Subprocessor is capable of providing performing the level of protection for Customer Personal Data required by obligations subcontracted to it in accordance with the AgreementAgreement (including this DPA); 5.2.2 4.4.2. ensure that the arrangement between on processing of Customer Data by the one hand (a) SentinelOne, or (b) the relevant intermediate Subprocessor; and on the other hand, the Subprocessor, Subprocessor is governed by a written contract including terms which offer at least the same level no less protective of protection for Customer Personal Data as than those set out in this Addendum and meet DPA and, if the requirements processing of Article 28(3) of the GDPR; 5.2.3 if that arrangement involves a Restricted TransferCustomer Personal Data is subject to European Data Protection Laws, ensure that the Standard Contractual Clauses data protection obligations in this DPA are at all relevant times incorporated into the agreement between imposed on the one hand (a) SentinelOne, or (b) the relevant intermediate Subprocessor; and 4.4.3. remain fully liable for all obligations subcontracted to, and on the other hand all acts and omissions of, the Subprocessor, or before the Subprocessor first Processes Customer Personal Data procure that it enters into an agreement incorporating the Standard Contractual Clauses with the Customer. and 5.2.4 provide to Customer for review such copies of the Contracted Processors' agreements with Subprocessors (which may be redacted to remove confidential commercial information not relevant to the requirements of this Addendum) as Customer may request from time to time. 5.3 SentinelOne shall ensure that each Subprocessor performs its obligations under sections 2.1, 3, 4, 6.1, 7.2, 8 and 10.1, as they apply to Processing of Customer Personal Data carried out by that Subprocessor, as if it were party to this Addendum in place of SentinelOne.

Appears in 2 contracts

Sources: Master Subscription Agreement, Data Protection Addendum

Subprocessing. 5.1 Customer authorises SentinelOne 4.1 You authorise us to appoint (and permit each Subprocessor appointed in accordance with this section 5 4 to appoint) Subprocessors in accordance with this section 5 4 and any restrictions in the Agreement. SentinelOne . 4.2 We may continue to use those Subprocessors already engaged by us as at the date of this Addendum, subject to us, in each case as soon as practicable, meeting the obligations set out in section 4.4. 4.3 We shall make available to Customer the current list of Subprocessors that are processing Customer Personal Data, attached as Annex 3. SentinelOne shall provide Customer give you prior written notice of the appointment of any new Subprocessor, including full details of the Processing to be undertaken by the Subprocessor. If, within thirty (30) 30 calendar days of receipt of that notice, Customer notifies SentinelOne you notify us in writing of any objections (on reasonable grounds) to the proposed appointment, and further provides commercially we shall not appoint (or disclose any of your Personal Data to) that proposed Subprocessor until it has taken reasonable justifications to such objections based on valid concerns regarding such proposed Subprocessor’s business practices relating to data protection, then (i) SentinelOne shall work with Customer in good faith steps to address Customer’s the objections regarding the new Subprocessor; raised by you and (ii) where Customer’s concerns cannot be resolved within thirty (30) days from SentinelOne's receipt of Customer's notice, notwithstanding anything in the Agreement, Customer may, by providing SentinelOne provided you with a reasonable written notice to with immediate effect, terminate explanation of the Agreement and SentinelOne shall refund to Customer all prepaid Fees for the Solutions attributable to the Subscription Term (as outlined in the applicable Purchase Order) following the termination of these Termssteps taken. 5.2 4.4 With respect to each Subprocessor, SentinelOne we shall: 5.2.1 4.4.1 before the Subprocessor first Processes Customer your Personal DataData (or, where relevant, in accordance with section 4.2), carry out adequate due diligence to ensure that the Subprocessor is capable of providing the level of protection for Customer your Personal Data required by the Agreement; 5.2.2 4.4.2 ensure that the arrangement between on the one hand us (a) SentinelOne, or (b) the relevant intermediate Subprocessor; ) and on the other hand, the Subprocessor, Subprocessor is governed by a written contract including terms which offer at least the same level of protection for Customer your Personal Data as those set out in this Addendum and meet the requirements of Article 28(3) of the GDPR;Addendum; and 5.2.3 4.4.3 if that arrangement involves a Restricted Transfer, ensure that the Standard Contractual Clauses are at all relevant times incorporated into the agreement between on the one hand us (a) SentinelOne, or (b) the relevant intermediate Subprocessor; ) and on the other hand the Subprocessor, or before the Subprocessor first Processes Customer your Personal Data procure that it enters into an agreement incorporating the Standard Contractual Clauses with you or we enter into the Customer. and 5.2.4 provide Standard Contract Contractual Clauses on your behalf and you hereby authorise us to Customer for review such copies of the Contracted Processors' agreements with Subprocessors (which may be redacted to remove confidential commercial information not relevant to the requirements of this Addendum) as Customer may request from time to timedo so. 5.3 SentinelOne shall ensure that each Subprocessor performs its obligations under sections 2.1, 3, 4, 6.1, 7.2, 8 and 10.1, as they apply to Processing of Customer Personal Data carried out by that Subprocessor, as if it were party to this Addendum in place of SentinelOne.

Appears in 2 contracts

Sources: Data Protection Addendum, Data Protection Addendum

Subprocessing. 5.1 Customer authorises SentinelOne Each Group Member authorizes Supplier and each Supplier Affiliate to appoint (and permit each Subprocessor appointed in accordance with this section 5 Section 4 to appoint) Subprocessors in accordance with this section 5 and any restrictions in the AgreementPrincipal Agreement and this Addendum. SentinelOne shall make available Supplier and each Supplier Affiliate may continue to Customer use those Subprocessors already engaged by Supplier or any Supplier Affiliate as at the current date of this Addendum, subject to Supplier and each Supplier Affiliate meeting the obligations set out in this Section and Supplier providing a list of any such Subprocessors that are processing Customer Personal Data, attached as Annex 3prior to the performance of Services. SentinelOne Supplier shall provide Customer give Us prior written notice of the appointment of any new Subprocessor, including full details of the location and Processing to be undertaken by the Subprocessor prior to or concurrent with the appointment of such Subprocessor. If, within thirty 30 (30thirty) calendar days of receipt of that notice, Customer notifies SentinelOne We notify Supplier in writing of any objections (on reasonable grounds) to the proposed appointment, then: ● Supplier will cancel its plan to use the Subprocessor for the processing of Cloud Software Group Personal Information and further provides commercially reasonable justifications will offer an alternative to provide the Services without such objections based on valid concerns regarding such proposed Subprocessor’s business practices relating to data protection, then (i) SentinelOne shall work with Customer in good faith to address Customer’s objections regarding the new Subprocessor; ● Supplier will take the corrective steps requested by Us in its objection(s) and proceed to use the Subprocessor to process Cloud Software Group Personal Information; or ● We may choose not to use the Services that would involve the use of such Subprocessor with regard to Personal Information, subject to adjustment of the remuneration for the Services considering the reduced scope of the Services. If none of the above options are reasonably available and all of Our objections have not been resolved to the mutual satisfaction of the Parties within 30 (iithirty) where Customer’s concerns cannot be resolved within thirty (30) calendar days from SentinelOneof the Supplier's receipt of Customer's noticeOur objection, notwithstanding anything either Party may terminate the applicable SOW or Order Form in accordance with the termination rights in the Principal Agreement, Customer may, by providing SentinelOne with a written notice to with immediate effect, terminate the Agreement and SentinelOne shall refund to Customer all prepaid Fees for the Solutions attributable to the Subscription Term (as outlined in the applicable Purchase Order) following the termination of these Terms. 5.2 . With respect to each Subprocessor, SentinelOne Supplier or the relevant Supplier Affiliate shall: 5.2.1 : ● before the Subprocessor first Processes Customer begins Processing Personal DataInformation, carry out adequate due diligence to ensure that the Subprocessor is capable of providing the level of protection for Customer Personal Data Information required by the Agreement; 5.2.2 this Addendum; ● ensure that the arrangement between on the one hand (a) SentinelOneSupplier or the relevant Supplier Affiliate, or and (b) the relevant intermediate Subprocessor; and on the other hand, the Subprocessor, is governed by a written contract including terms which offer at least the same level of protection for Customer Personal Data Information as those set out in this Addendum and meet the requirements of Article 28(3) of the GDPR; 5.2.3 if that arrangement involves a Restricted Transfer, ensure that the Standard Contractual Clauses are at all relevant times incorporated into the agreement between on the one hand (a) SentinelOne, or (b) the relevant intermediate SubprocessorAddendum; and on the other hand the Subprocessor, or before the Subprocessor first Processes Customer Personal Data procure that it enters into an agreement incorporating the Standard Contractual Clauses with the Customer. and 5.2.4 provide to Customer Us for review such copies of the Contracted Processors' agreements with Subprocessors (which may be redacted to remove confidential commercial information not relevant to the requirements of this Addendum) as Customer We may request from time to time. 5.3 SentinelOne . Supplier and each Supplier Affiliate shall ensure that be responsible for each Subprocessor performs such Subprocessor’s performance of its obligations under sections 2.1and compliance with the terms of the Principal Agreement, 3, 4, 6.1, 7.2, 8 and 10.1, as they apply to Processing of Customer Personal Data carried out by that Subprocessor, as if it were party to this Addendum in place of SentinelOneand Applicable Law.

Appears in 2 contracts

Sources: Data Processing Addendum, Data Processing Addendum

Subprocessing. 5.1 Customer 6.1 Each Company Group Member authorises SentinelOne Vendor and each Vendor Affiliate to appoint (and permit each Subprocessor appointed in accordance with this section 5 6 to appoint) Subprocessors in accordance with this section 5 6 and any restrictions in the Principal Agreement. SentinelOne . 6.2 Vendor and each Vendor Affiliate may continue to use those Subprocessors already engaged by Vendor or any Vendor Affiliate as at the date of this Addendum, subject to Vendor and each Vendor Affiliate in each case as soon as practicable meeting the obligations set out in section 6.4. 6.3 Vendor shall make available to Customer the current list of Subprocessors that are processing Customer Personal Data, attached as Annex 3. SentinelOne shall provide Customer give Company prior written notice of the appointment of any new Subprocessor, including full details of the Processing to be undertaken by the Subprocessor. If, within thirty (30) days of receipt of that notice, Customer Company notifies SentinelOne Vendor in writing of any objections (on reasonable grounds) to the proposed appointment, and further provides commercially reasonable justifications to such objections based on valid concerns regarding such : Neither Vendor nor any Vendor Affiliate shall appoint (nor disclose any Company Personal Data to) the proposed Subprocessor’s business practices relating to data protection, then (i) SentinelOne shall work Subprocessor except with Customer in good faith to address Customer’s objections regarding the new Subprocessor; and (ii) where Customer’s concerns cannot be resolved within thirty (30) days from SentinelOne's receipt prior written consent of Customer's notice, notwithstanding anything in the Agreement, Customer may, by providing SentinelOne with a written notice to with immediate effect, terminate the Agreement and SentinelOne shall refund to Customer all prepaid Fees for the Solutions attributable to the Subscription Term (as outlined in the applicable Purchase Order) following the termination of these TermsCompany. 5.2 6.4 With respect to each Subprocessor, SentinelOne Vendor or the relevant Vendor Affiliate shall: 5.2.1 6.4.1 before the Subprocessor first Processes Customer Company Personal DataData (or, where relevant, in accordance with section 6.2), carry out adequate due diligence to ensure that the Subprocessor is capable of providing the level of protection for Customer Company Personal Data required by the Principal Agreement; 5.2.2 6.4.2 ensure that the arrangement between on the one hand (a) SentinelOneVendor, or (b) the relevant Vendor Affiliate, or (c) the relevant intermediate Subprocessor; and on the other hand, hand the Subprocessor, is governed by a written contract including terms which offer at least the same level of protection for Customer Company Personal Data as those set out in this Addendum and meet the requirements of Article article 28(3) of the GDPR; 5.2.3 if that arrangement involves a Restricted Transfer, ensure that the Standard Contractual Clauses are at all relevant times incorporated into the agreement between on the one hand (a) SentinelOne, or (b) the relevant intermediate Subprocessor; and on the other hand the Subprocessor, or before the Subprocessor first Processes Customer Personal Data procure that it enters into an agreement incorporating the Standard Contractual Clauses with the Customer. and 5.2.4 6.4.3 provide to Customer Company for review such copies of the Contracted Processors' agreements with Subprocessors (which may be redacted to remove confidential commercial information not relevant to the requirements of this Addendum) as Customer Company may request from time to time. 5.3 SentinelOne 6.5 Vendor and each Vendor Affiliate shall ensure that each Subprocessor performs its the obligations under sections 2.1, 33.1, 4, 6.15, 7.27.1, 8 8.2, 9 and 10.111.1, as they apply to Processing of Customer Company Personal Data carried out by that Subprocessor, as if it were party to this Addendum in place of SentinelOneVendor.

Appears in 2 contracts

Sources: Data Protection Addendum, Data Protection Addendum

Subprocessing. 5.1 Customer authorises SentinelOne Each Company Group Member authorizes Vendor to appoint (and permit each Subprocessor appointed in accordance with section 6 of this section 5 DPA to appoint) Subprocessors in accordance with this section 5 and any restrictions in the Agreement. SentinelOne . 5.2 Vendor may continue to use those Subprocessors already engaged by Vendor as at the date of this DPA, subject to Vendor in each case as soon as practicable meeting the obligations set out in section 5.4. 5.3 Vendor shall make available to Customer the current list of Subprocessors that are processing Customer Personal Data, attached as Annex 3. SentinelOne shall provide Customer give Company prior written notice of the appointment of any new Subprocessor, including full details of the Processing to be undertaken by the Subprocessor. If, within thirty (30) 14 Calendar days of receipt of that notice, Customer notifies SentinelOne Company notifies Vendor in writing of any objections (on reasonable grounds) to the proposed appointment, and further provides commercially : Vendor shall not appoint (or disclose any Company Personal Data to) the proposed Subprocessor until reasonable justifications to such objections based on valid concerns regarding such proposed Subprocessor’s business practices relating to data protection, then (i) SentinelOne shall work with Customer in good faith steps have been taken to address Customer’s the objections regarding the new Subprocessor; raised by any Company Group Member and (ii) where Customer’s concerns cannot be resolved within thirty (30) days from SentinelOne's receipt of Customer's notice, notwithstanding anything in the Agreement, Customer may, by providing SentinelOne Company has been provided with a reasonable written notice to with immediate effect, terminate explanation of the Agreement and SentinelOne shall refund to Customer all prepaid Fees for the Solutions attributable to the Subscription Term (as outlined in the applicable Purchase Order) following the termination of these Termssteps taken. 5.2 5.4 With respect to each Subprocessor, SentinelOne Vendor shall: 5.2.1 5.4.1 before the Subprocessor first first Processes Customer Company Personal DataData (or, where relevant, in accordance with section 5.2), carry out adequate due diligence to ensure that the Subprocessor is capable of providing the level of protection for Customer Company Personal Data required by the Agreement; 5.2.2 5.4.2 ensure that the arrangement between on the one hand (a) SentinelOne, Vendor or (b) the relevant intermediate Subprocessor; and on the other hand, hand the Subprocessor, is governed by a written contract including terms which offer at least the same level of protection for Customer Company Personal Data as those set out in this Addendum DPA and meet the requirements of Article article 28(3) of the GDPR; 5.2.3 if that arrangement involves a Restricted Transfer, ensure that the Standard Contractual Clauses are at all relevant times incorporated into the agreement between on the one hand (a) SentinelOne, or (b) the relevant intermediate Subprocessor; and on the other hand the Subprocessor, or before the Subprocessor first Processes Customer Personal Data procure that it enters into an agreement incorporating the Standard Contractual Clauses with the Customer. and 5.2.4 5.4.3 upon request provide to Customer Company for review such copies of the Contracted Processors' Processors agreements with Subprocessors (which may be redacted to remove confidential confidential commercial information not relevant to the requirements of this AddendumDPA) as Customer Company may request from time to time. 5.3 SentinelOne 5.5 Vendor shall ensure that each Subprocessor performs its the obligations under sections 2.1, 3, 4, 6.1, 7.2, 8 and 10.1, this DPA as they apply to Processing of Customer Company Personal Data carried out by that Subprocessor, as if it were party to this Addendum DPA in place of SentinelOneVendor.

Appears in 2 contracts

Sources: Data Protection Addendum, Data Protection Addendum

Subprocessing. 5.1 Customer authorises SentinelOne 5.1. Vendor shall not engage any Subprocessor or disclose any Company Personal Data to appoint any third party without Company’s prior specific written authorization. Vendor shall submit the request for specific authorization to Company (and permit each by email to ▇▇▇▇▇▇▇▇▇▇▇@▇▇▇▇▇▇▇▇▇▇▇▇▇▇.▇▇▇) at least one month in advance of its engagement of a new Subprocessor. The request to engage a new Subprocessor appointed should include (i) the identity of the new Subprocessor, (ii) the location in accordance with this section 5 to appoint) Subprocessors in accordance with this section 5 and any restrictions in which the Agreement. SentinelOne shall make available to Customer the current list of Subprocessors that are processing Customer Subprocessor would Process Company Personal Data, attached as Annex 3. SentinelOne shall provide Customer prior written notice (iii) a description of the appointment of any new Subprocessor, including details of the relevant Processing operations to be undertaken carried out by the Subprocessor. If, within thirty (30) days of receipt of that notice, Customer notifies SentinelOne in writing of any objections to the proposed appointment, and further provides commercially reasonable justifications to such objections based on valid concerns regarding such proposed Subprocessor’s business practices relating to data protection, then (iiv) SentinelOne shall work with Customer in good faith to address Customer’s objections regarding the new Subprocessor; and (ii) where Customer’s concerns cannot be resolved within thirty (30) days from SentinelOne's receipt of Customer's notice, notwithstanding anything in the Agreement, Customer may, any other information reasonably requested by providing SentinelOne with a written notice to with immediate effect, terminate the Agreement and SentinelOne shall refund to Customer all prepaid Fees for the Solutions attributable to the Subscription Term (as outlined in the applicable Purchase Order) following the termination of these TermsCompany. 5.2 With respect 5.2. To the extent that Company authorizes Vendor to engage a Subprocessor (“Authorized Subprocessor”): (a) Vendor shall evaluate the security, privacy and confidentiality practices of each Subprocessor, SentinelOne shall: 5.2.1 before the Authorized Subprocessor first Processes Customer Personal Data, carry out adequate due diligence to ensure establish that the such Subprocessor is capable of providing the level of protection for Customer Personal Data required by the Agreementthis DPA; 5.2.2 ensure that the arrangement between on the one hand (a) SentinelOne, or (b) the relevant intermediate Subprocessor; and on the other hand, the Subprocessor, Vendor shall ensure that each Authorized Subprocessor is governed bound by a written contract including terms which offer agreement that, at least a minimum, binds Authorized Subprocessor to the same level of data protection for Customer obligations as those applicable to Vendor under this DPA. Such agreement must also include a third-party beneficiary clause whereby, in the event Vendor factually disappears, ceases to exist in law or becomes insolvent, Company shall have the right to terminate Vendor’s agreement with Authorized Subprocessor and instruct Authorized Subprocessor to destroy or return Company Personal Data as those to Company. Vendor shall be responsible for ensuring Authorized Subprocessors comply with the obligations in such agreements and Data Protection Laws; (c) If Vendor transfers Company Personal Data to Authorized Subprocessor for Processing in a Third Country, Vendor shall utilize a transfer mechanism that complies with Data Protection Laws; and (d) Vendor shall notify Company when its Authorized Subprocessor appoints a Subprocessor to Process Company Personal Data and comply with the requirements set out in this Addendum and meet the requirements of Article 28(3) Section 5 of the GDPR;DPA. 5.2.3 if that arrangement involves 5.3. Upon request, Vendor shall provide (i) a Restricted Transferlist of Subprocessors to Company, ensure that the Standard Contractual Clauses are at all relevant times incorporated into the agreement between on the one hand and (aii) SentinelOne, or (b) the relevant intermediate Subprocessor; and on the other hand the Subprocessor, or before the Subprocessor first Processes Customer Personal Data procure that it enters into an agreement incorporating the Standard Contractual Clauses with the Customer. and 5.2.4 provide to Customer for review such copies a copy of the Contracted Processors' agreements with Subprocessors (which and any subsequent amendments thereto. Vendor may be redacted to remove confidential commercial information not relevant redact such agreements to the requirements of this Addendum) as Customer may request from time extent necessary to timeprotect business secrets, other confidential information and Personal Data. 5.3 SentinelOne 5.4. Vendor shall ensure that remain fully liable to Company for the performance of each Subprocessor’s obligations in accordance with this DPA. Vendor shall notify Company of any failure by a Subprocessor performs to fulfill its obligations under sections 2.1, 3, 4, 6.1, 7.2, 8 and 10.1, as they apply to Processing of Customer Personal Data carried out by that Subprocessor, as if it were party to this Addendum in place of SentinelOnecontractual obligations.

Appears in 2 contracts

Sources: Data Processing Agreement, Data Processing Agreement

Subprocessing. 5.1 Customer authorises SentinelOne 6.1 Vendor shall only appoint subprocessors which enable Vendor to appoint (comply with Privacy Laws and permit this DPA, and Vendor shall obtain prior written authorisation in respect of each Subprocessor appointed in accordance with this section 5 subprocessor and shall not use any subprocessor to appoint) Subprocessors in accordance with this section 5 and any restrictions undertake Processing of the Protected Data without the prior written authorisation of Verint. Prior written authorisation includes where such subprocessors are referred to in the Cover Page of this DPA or otherwise agreed in writing by ▇▇▇▇▇▇, and each such authorised subprocessor shall deemed to be an Authorised Subprocessor for the purposes of this DPA and the Principal Agreement. SentinelOne shall make available to Customer . 6.2 Where ▇▇▇▇▇▇’s written authorisation in respect of an Authorised Subprocessor is included in the current list Cover Page of Subprocessors that are processing Customer Personal Datathis DPA and therefore such Authorised Subprocessor is classified as an existing appointed subprocessor of the Vendor, attached as Annex 3. SentinelOne then Vendor shall provide Customer prior written notice of evidence upon ▇▇▇▇▇▇’s request to enable Verint to verify the appointment of any new Authorised Subprocessor, including details of ’s activities relating to the Processing to be undertaken by the Subprocessor. If, within thirty (30) days of receipt of that notice, Customer notifies SentinelOne in writing of any objections to the proposed appointment, and further provides commercially reasonable justifications to such objections based on valid concerns regarding such proposed Subprocessor’s business practices relating to data protection, then (i) SentinelOne shall work with Customer in good faith to address Customer’s objections regarding the new Subprocessor; and (ii) where Customer’s concerns cannot be resolved within thirty (30) days from SentinelOne's receipt of Customer's notice, notwithstanding anything in the Agreement, Customer may, by providing SentinelOne with a written notice to with immediate effect, terminate the Agreement and SentinelOne shall refund to Customer all prepaid Fees for the Solutions attributable to the Subscription Term (as outlined in the applicable Purchase Order) following the termination of these TermsProtected Data. 5.2 6.3 With respect to each Authorised Subprocessor, SentinelOne Vendor shall: 5.2.1 6.3.1 before the Authorised Subprocessor first Processes Customer Personal DataProtected Data (or, where relevant, in accordance with Section 6.2), carry out adequate due diligence to ensure that the Authorised Subprocessor is capable of providing the level of protection for Customer Personal Protected Data required by the AgreementPrincipal Agreement and this DPA and upon Verint’s request provide written evidence thereof; 5.2.2 6.3.2 ensure that the arrangement between each Authorised Subprocessor is subject to a Written Subcontract and ensure that each Written Subcontract contains a prohibition on the one hand (a) SentinelOne, or (b) the relevant intermediate Subprocessor; and on the other hand, the Subprocessor, is governed by a written contract including terms which offer at least the same level of protection for Customer Personal Data as those set out in this Addendum and meet the requirements of Article 28(3) further subcontracting of the GDPRProcessing of Protected Data (to any other subprocessor) unless with ▇▇▇▇▇▇’s prior written consent; 5.2.3 if that arrangement involves a Restricted Transfer, 6.3.3 ensure that the Written Subcontract incorporates the Standard Contractual Clauses are at all relevant times incorporated into in respect of any Processing by the agreement between on the one hand (a) SentinelOne, or (b) the relevant intermediate SubprocessorAuthorised Subcontractor that involves an Authorised Transfer under this DPA; and on the other hand the Subprocessor, or before the Subprocessor first Processes Customer Personal Data procure that it enters into an agreement incorporating the Standard Contractual Clauses with the Customer. and 5.2.4 6.3.4 provide to Customer Verint for review such copies a copy of the Contracted Processors' agreements Written Subcontract as Verint may request from time to time to enable Verint to verify compliance with Subprocessors this Section 6 (which copy may be redacted to remove confidential commercial information not relevant to the requirements of this Addendum) as Customer may request from time to timeDPA). 5.3 SentinelOne 6.4 Vendor shall ensure that each Authorised Subprocessor performs its the obligations under sections 2.1, Sections 3, 4, 6.15, 7.26, 8 7.1, 8.1, 9 and 10.1, as they apply to Processing of Customer Personal Protected Data carried out by that Authorised Subprocessor, as if it were party to this Addendum DPA in place of SentinelOneVendor.

Appears in 2 contracts

Sources: Data Processing Agreement, Data Privacy & Security

Subprocessing. 5.1 Customer 1. Each Company Group Member authorises SentinelOne Vendor and each Vendor Affiliate to appoint (and permit each Subprocessor appointed in accordance with this section 5 to appoint) Subprocessors in accordance with this section 5 and any restrictions in the Agreement. 2. SentinelOne shall make available Vendor and each Vendor Affiliate may continue to Customer use those Subprocessors already engaged by Vendor or any Vendor Affiliate as at the current list date of Subprocessors that are processing Customer Personal Datathis Addendum, attached subject to Vendor and each Vendor Affiliate in each case as Annex soon as practicable meeting the obligations set out in section 5.4. 3. SentinelOne Vendor shall provide Customer give Company prior written notice of the appointment of any new Subprocessor, including full details of the Processing to be undertaken by the Subprocessor. If, within thirty (30) 30 days of receipt of that notice, Customer Company notifies SentinelOne Vendor in writing of any objections (on reasonable grounds) to the proposed appointment, and further provides commercially : Neither Vendor nor any Vendor Affiliate shall appoint (or disclose any Company Personal Data to) that proposed Subprocessor until reasonable justifications to such objections based on valid concerns regarding such proposed Subprocessor’s business practices relating to data protection, then (i) SentinelOne shall work with Customer in good faith steps have been taken to address Customer’s the objections regarding the new Subprocessor; raised by any Company Group Member and (ii) where Customer’s concerns cannot be resolved within thirty (30) days from SentinelOne's receipt of Customer's notice, notwithstanding anything in the Agreement, Customer may, by providing SentinelOne Company has been provided with a reasonable written notice to with immediate effect, terminate explanation of the Agreement and SentinelOne shall refund to Customer all prepaid Fees for the Solutions attributable to the Subscription Term (as outlined in the applicable Purchase Order) following the termination of these Termssteps taken. 5.2 4. With respect to each Subprocessor, SentinelOne Vendor or the relevant Vendor Affiliate shall: 5.2.1 1. before the Subprocessor first Processes Customer Company Personal DataData (or, where relevant, in accordance with section 5.2), carry out adequate due diligence to ensure that the Subprocessor is capable of providing the level of protection for Customer Company Personal Data required by the Agreement; 5.2.2 2. ensure that the arrangement between on the one hand (a) SentinelOneVendor, or (b) the relevant Vendor Affiliate, or (c) the relevant intermediate Subprocessor; and on the other hand, hand the Subprocessor, is governed by a written contract including terms which offer at least the same level of protection for Customer Company Personal Data as those set out in this Addendum and meet the requirements of Article article 28(3) of the GDPR; 5.2.3 3. if that arrangement involves a Restricted Transfer, ensure that the Standard Contractual Clauses are at all relevant times incorporated into the agreement between on the one hand hand (a) SentinelOneVendor, or (b) the relevant Vendor Affiliate, or (c) the relevant intermediate Subprocessor; and on the other hand the Subprocessor, or before the Subprocessor first Processes Customer Company Personal Data procure that it enters into an agreement incorporating the Standard Contractual Clauses with the Customer. relevant Company Group Member(s); and 5.2.4 4. provide to Customer Company for review such copies of the Contracted Processors' agreements with Subprocessors (which may be redacted to remove confidential commercial information not relevant to the requirements of this Addendum) as Customer Company may request from time to time. 5.3 SentinelOne 5. Vendor and each Vendor Affiliate shall ensure that each Subprocessor performs its obligations under sections 2.1, 3, 4, 6.1, 7.2, 8 and 10.1the obligations, as they apply to Processing of Customer Company Personal Data carried out by that Subprocessor, as if it were party to this Addendum in place of SentinelOneVendor.

Appears in 2 contracts

Sources: Terms of Use, Data Processing Agreement

Subprocessing. 5.1 To the extent required under Applicable Laws, Customer authorises SentinelOne authorizes CrowdStrike to appoint (and permit each Subprocessor appointed in accordance with this section 5 to appoint) Subprocessors in accordance with this section 5 6 and any restrictions in the Agreement. SentinelOne shall make available . 5.2 CrowdStrike may continue to use those Subprocessors already engaged as of the date of this DPA specified in Exhibit E, subject to CrowdStrike in each case meeting the obligations set out in section 5.5. 5.3 Customer the current agrees to CrowdStrike maintaining and updating its list of Subprocessors that are processing online, for the Falcon Platform and Humio as outlined in Exhibit E. 5.4 CrowdStrike shall provide notice of a proposed new Subprocessor to the Customer, at least 30 days prior to CrowdStrike’s use of the new Subprocessor to Process Customer Personal Data, attached as Annex 3through the applicable CrowdStrike Offering or platform, where Customer may elect to subscribe to such notices. SentinelOne shall provide Customers may sign up for email Subprocessor notifications at ▇▇▇▇▇://▇▇▇.▇▇▇▇▇▇▇▇▇▇▇.▇▇▇/subprocessor-notification/. During the notice period, Customer prior may object to a change in Subprocessor in writing and CrowdStrike may, in its sole discretion, attempt to resolve Customer’s objection, including providing the Offerings without use of the proposed Subprocessor. If (a) CrowdStrike provides Customer written notice of the appointment of any new Subprocessorthat it will not pursue an alternative, including details of the Processing to be undertaken by the Subprocessor. If, within thirty or (30b) days of receipt of that notice, Customer notifies SentinelOne in writing of any objections to the proposed appointment, and further provides commercially reasonable justifications to such objections based on valid concerns regarding such proposed Subprocessor’s business practices relating to data protection, then (i) SentinelOne shall work with Customer in good faith to address Customer’s objections regarding the new Subprocessor; and (ii) where Customer’s concerns an alternative cannot be resolved made available by CrowdStrike to Customer within thirty (30) 90 days from SentinelOne's receipt of Customer's noticeCustomer providing notice of its objection, then in either case, and notwithstanding anything to the contrary in the AgreementAgreement or order, Customer may, by providing SentinelOne with a written notice to with immediate effect, may terminate the Agreement and SentinelOne shall refund to Customer all prepaid Fees for the Solutions attributable or order to the Subscription Term (as outlined in extent that it relates to the applicable Purchase Order) following Offerings which require the termination use of these Termsthe proposed Subprocessor. 5.2 5.5 With respect to each Subprocessor, SentinelOne to the extent required under Applicable Laws, CrowdStrike shall: 5.2.1 before 5.5.1 Before the Subprocessor first Processes Customer Personal DataData (or, where relevant, in accordance with section 5.2), carry out adequate due diligence to ensure that the Subprocessor is capable of providing the level of protection for Customer Personal Data required by Applicable Laws, this DPA and the Agreement; 5.2.2 ensure 5.5.2 Ensure that the arrangement between on the one hand (a) SentinelOne, or (b) the relevant intermediate Subprocessor; CrowdStrike and on the other hand, the Subprocessor, Subprocessor is governed by a written contract including terms which offer at least offers substantially the same level of protection for Customer Personal Data as those set out required by this DPA and Applicable Laws, including Customer’s ability to protect the rights of Data Subjects in this Addendum and meet the requirements of Article 28(3) of the GDPRevent CrowdStrike is insolvent, liquidated or otherwise ceases to exist; 5.2.3 if that arrangement 5.5.3 Apply an adequacy mechanism recognized by Customer’s Supervisory Authority as ensuring an adequate level of data protection under Applicable Laws where Subprocessor’s Processing of Customer Personal Data involves a Restricted Transfer, ensure that the Standard Contractual Clauses are at all relevant times incorporated into the agreement between on the one hand; (a) SentinelOne, or (b) the relevant intermediate Subprocessor; and on the other hand the Subprocessor, or before the Subprocessor first Processes Customer Personal Data procure that it enters into an agreement incorporating the Standard Contractual Clauses with the Customer. and 5.2.4 provide to Customer for review such 5.5.4 Maintain copies of the Contracted Processors' agreements with Subprocessors (which may be redacted to remove confidential commercial information not relevant to the requirements of this Addendum) as Customer may request from time to time.. To the extent necessary to protect Confidential Information, CrowdStrike may redact the copies prior to sharing with Customer; and 5.3 SentinelOne shall ensure that each Subprocessor performs its 5.5.5 Notify Customer of Subprocessor’s relevant failure to comply with obligations under sections 2.1, 3, 4, 6.1, 7.2, 8 and 10.1, as they apply to Processing of Customer Personal Data carried set out by that Subprocessor, as if it were party to Applicable Laws and this Addendum in place DPA where CrowdStrike has received notice of SentinelOnesuch.

Appears in 2 contracts

Sources: Data Protection Agreement, Data Protection Agreement

Subprocessing. 5.1 Customer ‌ 6.1 Each Tata Communications Group Member authorises SentinelOne Vendor and each Vendor Affiliate to appoint (and permit each Subprocessor appointed in accordance with this section 5 Section 6 to appoint) Subprocessors in accordance with this section 5 Section 6 and any restrictions in the Principal Agreement. SentinelOne . 6.2 Vendor and each Vendor Affiliate may continue to use those Subprocessors already engaged by Vendor or any Vendor Affiliate as at the date of this Addendum, subject to Vendor and each Vendor Affiliate in each case as soon as practicable meeting the obligations set out in Section 6.4.‌ 6.3 Vendor shall make available to Customer the current list of Subprocessors that are processing Customer Personal Data, attached as Annex 3. SentinelOne shall provide Customer give Tata Communications prior written notice of the appointment of any new Subprocessor, including full details of the Processing to be undertaken by the Subprocessor. If, within thirty ten (3010) business days of receipt of that notice, Customer Tata Communications notifies SentinelOne Vendor in writing of any objections (on reasonable grounds) to the proposed appointment, and further provides commercially reasonable justifications to such objections based on valid concerns regarding such proposed Subprocessor’s business practices relating to data protection, then (i) SentinelOne : 6.3.1 Vendor shall work with Customer Tata Communications in good faith to address Customer’s objections regarding make available a commercially reasonable change in the new provision of the Services which avoids the use of that proposed Subprocessor; and (ii) and 6.3.2 where Customer’s concerns such a change cannot be resolved made within thirty ten (3010) business days from SentinelOneVendor's receipt of Customer's Tata Communications' notice, notwithstanding anything in the Principal Agreement, Customer may, Tata Communications may by providing SentinelOne with a written notice to Vendor with immediate effect, effect terminate the Principal Agreement and SentinelOne shall refund to Customer all prepaid Fees for the Solutions attributable to the Subscription Term (as outlined in extent that it relates to the applicable Purchase Order) following Services which require the termination use of these Termsthe proposed Subprocessor. 5.2 6.4 With respect to each Subprocessor, SentinelOne shall:Vendor or the relevant Vendor Affiliate shall:‌ 5.2.1 6.4.1 before the Subprocessor first Processes Customer Tata Communications Personal DataData (or, where relevant, in accordance with Section 6.2), carry out adequate due diligence to ensure that the Subprocessor is capable of providing the level of protection for Customer Tata Communications Personal Data required by this Addendum and the Principal Agreement; 5.2.2 6.4.2 ensure that the arrangement between on the one hand (a) SentinelOneVendor, or (b) the relevant Vendor Affiliate, or (c) the relevant intermediate Subprocessor; and on the other hand, hand the Subprocessor, is governed by a written contract including terms which offer at least the same level of protection for Customer Tata Communications Personal Data as those set out in this Addendum and meet the requirements of Article 28(3) of the GDPR; 5.2.3 6.4.3 if that arrangement involves a Restricted Transfer, ensure that the Standard Contractual Clauses are at all relevant times incorporated into the agreement between on the one hand hand (a) SentinelOneVendor, or (b) the relevant Vendor Affiliate, or (c) the relevant intermediate Subprocessor; and on the other hand the Subprocessor, or before the Subprocessor first Processes Customer Tata Communications Personal Data procure that it enters into an agreement incorporating the Standard Contractual Clauses with the Customer. andrelevant Tata Communications Group Member(s) (and Tata Communications shall procure that each Tata Communications Affiliate party to any such Standard Contractual Clauses co-operates with their population and execution); and‌ 5.2.4 6.4.4 provide to Customer Tata Communications for review such copies of the Contracted Processors' agreements with Subprocessors (which may be redacted to remove confidential commercial information not relevant to the requirements of this Addendum) as Customer Tata Communications may request from time to time. 5.3 SentinelOne 6.5 Vendor and each Vendor Affiliate shall ensure that each Subprocessor performs its the obligations under sections 2.1, 33.1, 4, 6.15, 7.27.1, 8 8.2, 9 and 10.111.1, as they apply to Processing of Customer Tata Communications Personal Data carried out by that Subprocessor, as if it were party to this Addendum in place of SentinelOneVendor.

Appears in 1 contract

Sources: Data Protection Addendum

Subprocessing. 5.1 Customer authorises SentinelOne to appoint (and permit each Subprocessor appointed in accordance with this section 5 to appoint) Subprocessors in accordance with this section 5 and any restrictions in the Agreement. SentinelOne shall make available to Customer the current list of Subprocessors that ‌ The following provisions are processing Customer Personal Data, attached as Annex 3. SentinelOne shall provide Customer prior written notice of the appointment of any new Subprocessor, including details of the Processing to be undertaken by the Subprocessor. If, within thirty (30) days of receipt of that notice, Customer notifies SentinelOne in writing of any objections without prejudice to the proposed appointment, content of Clause 9(a) SCC option 2 and further provides commercially reasonable justifications to such objections based on valid concerns regarding such proposed Subprocessor’s business practices relating to data protection, then (iClause 9(b) SentinelOne shall work with Customer in good faith to address SCC: 8.1 Carrot has Customer’s objections regarding the new Subprocessor; and (ii) where Customer’s concerns cannot be resolved within thirty (30) days from SentinelOne's receipt of Customer's notice, notwithstanding anything in the Agreement, Customer may, by providing SentinelOne with a written notice to with immediate effect, terminate the Agreement and SentinelOne shall refund to Customer all prepaid Fees Affiliates’ general authorization for the Solutions attributable to the Subscription Term (as outlined in the applicable Purchase Orderengagement of sub- processor(s) following the termination of these Terms. 5.2 With with respect to each Subprocessor, SentinelOne shall: 5.2.1 before the Subprocessor first Processes Customer Personal Data, carry out adequate due diligence to ensure that the Subprocessor is capable of providing the level of protection for Customer Personal Data required by from an agreed list. Customer herewith agrees also on behalf of its Customer Affiliates to the Agreement;sub-processors as set out in Exhibit C. 5.2.2 ensure 8.2 Carrot may provide a website or provide another written notice that the arrangement between on the one hand (a) SentinelOne, or (b) the relevant intermediate Subprocessor; and on the other hand, the Subprocessor, is governed by a written contract including terms which offer at least the same level of protection for lists all sub-processors to access Customer Personal Data as those set out well as the limited or ancillary services they perform. Carrot shall not authorize any new sub-processor except where Carrot has provided Customer with at least two (2) weeks’ prior notice by electronic means or via email and the opportunity to object to such sub-processor in this Addendum and meet accordance with the requirements of Article 28(3aforementioned Clause to access Customer Personal Data.‌ 8.3 In the case that Customer objects to the sub-processing, Carrot will, at its discretion, use reasonable endeavors to make available to the Customer a change in the Services, or will recommend a commercially reasonable change to the Services to prevent the applicable sub-processor from processing the Customer Personal Data. If Carrot determines, at its discretion, that such a change is not viable, Carrot can choose to (i) either not engage the sub-processor, or (ii) to terminate the Agreement or any related service agreement with two (2) months prior written notice. Until the termination of the GDPR;Agreement or any related service agreement, Carrot may suspend the portion of the Services which is affected by the objection of Customer. Customer shall not be entitled to a pro-rata refund of the remuneration for the Services, unless the objection is based on justified reasons of non-compliance with applicable data protection law. 5.2.3 if that arrangement involves 8.4 Any sub-processor is obliged before initiating the processing, to commit itself by way of written contract to comply with, in substance, the same data protection obligations as the ones under the Data Processing Agreement. 8.5 Where a Restricted Transfersub-processor refuses to be bound by the same data protection obligations as the ones under the Data Processing Agreement, ensure that Customer may consent to such other terms whereby such consent shall not be unreasonably withheld if, upon request of the Standard Contractual Clauses are at all relevant times incorporated into the agreement between on the one hand (a) SentinelOneCustomer, or (b) the relevant intermediate Subprocessor; and on the other hand the Subprocessor, or before the Subprocessor first Processes Customer Personal Data procure that it enters into an agreement incorporating the Standard Contractual Clauses Carrot can demonstrate sub-processor’s compliance with the Customer. and 5.2.4 provide to Customer for review such copies of the Contracted Processors' agreements with Subprocessors (which may be redacted to remove confidential commercial information not relevant to the requirements of this Addendum) as Customer may request from time to timeApplicable Law. 5.3 SentinelOne shall ensure that each Subprocessor performs its obligations under sections 2.1, 3, 4, 6.1, 7.2, 8 and 10.1, as they apply to Processing of Customer Personal Data carried out by that Subprocessor, as if it were party to this Addendum in place of SentinelOne.

Appears in 1 contract

Sources: Data Processing Agreement

Subprocessing. 5.1 Customer Company authorises SentinelOne AccuRun to appoint (and permit each Subprocessor appointed in accordance with this section Section 5 to appoint) Subprocessors in accordance with this section Section 5 and any restrictions in the Principal Agreement. SentinelOne . 5.2 AccuRun may continue to use those Subprocessors already engaged by AccuRun as at the date of this Addendum, subject to AccuRun as soon as practicable meeting the obligations set out in Section 5.4. 5.3 AccuRun shall make available to Customer the current list of Subprocessors that are processing Customer Personal Data, attached as Annex 3. SentinelOne shall provide Customer give Company prior written notice of the appointment of any new Subprocessor, including full details of the Processing to be undertaken by the Subprocessor. If, within thirty (30) days of receipt of that notice, Customer Company notifies SentinelOne AccuRun in writing of any objections (on reasonable grounds) to the proposed appointment, and further provides commercially reasonable justifications to such objections based on valid concerns regarding such proposed Subprocessor’s business practices relating to data protection, then (i) SentinelOne : 5.3.1 AccuRun shall work with Customer Company in good faith to address Customer’s objections regarding make available a commercially reasonable change in the new provision of the Services which avoids the use of that proposed Subprocessor; and (ii) and 5.3.2 where Customer’s concerns such a change cannot be resolved made within thirty (30) days from SentinelOneAccuRun's receipt of CustomerCompany's notice, notwithstanding anything in the Principal Agreement, Customer may, Company may by providing SentinelOne with a written notice to AccuRun with immediate effect, effect terminate the Principal Agreement and SentinelOne shall refund to Customer all prepaid Fees for the Solutions attributable to the Subscription Term (as outlined in extent that it relates to the applicable Purchase Order) following Services which require the termination use of these Termsthe proposed Subprocessor. 5.2 5.4 With respect to each Subprocessor, SentinelOne AccuRun or shall: 5.2.1 5.4.1 before the Subprocessor first Processes Customer Company Personal DataData (or, where relevant, in accordance with Section 5.2), carry out adequate due diligence to ensure that the Subprocessor is capable of providing the level of protection for Customer Company Personal Data required by the Principal Agreement; 5.2.2 5.4.2 ensure that the arrangement between on the one hand (a) SentinelOneAccuRun, or (bc) the relevant intermediate Subprocessor; and on the other hand, hand the Subprocessor, is governed by a written contract including terms which offer at least the same level of protection for Customer Company Personal Data as those set out in this Addendum and meet the requirements of Article article 28(3) of the GDPR; 5.2.3 5.4.3 if that arrangement involves a Restricted Transfer, ensure that the Standard Contractual Clauses are at all relevant times incorporated into the agreement between on the one hand hand (a) SentinelOneAccuRun, or (bc) the relevant intermediate Subprocessor; and on the other hand the Subprocessor, or before the Subprocessor first Processes Customer Company Personal Data procure that it enters into an agreement incorporating the Standard Contractual Clauses with the Customer. Company; and 5.2.4 5.4.4 provide to Customer Company for review such copies of the Contracted Processors' agreements with Subprocessors (which may be redacted to remove confidential commercial information not relevant to the requirements of this Addendum) as Customer Company may request from time to time. 5.3 SentinelOne 5.5 AccuRun shall ensure that each Subprocessor performs its the obligations under sections 2.1Sections 2.2, 3, 4, 6.1, 7.2, 8 and 8, 10.1, as they apply to Processing of Customer Company Personal Data carried out by that Subprocessor, as if it were party to this Addendum in place of SentinelOneAccuRun.

Appears in 1 contract

Sources: Data Protection Addendum

Subprocessing. 5.1 6.1. Customer authorises SentinelOne authorizes Dubsado and each Dubsado Affiliate to appoint (and permit each Subprocessor Sub- processor appointed in accordance with this section 5 6 to appoint) Subprocessors Sub-processors in accordance with this section 5 6 and any restrictions in the Principal Agreement. 6.2. SentinelOne shall make available Dubsado and each Dubsado Affiliate may continue to Customer use those Sub-processors already engaged by Dubsado or any Dubsado Affiliate as at the current date of this Addendum, subject to Dubsado and each Dubsado Affiliate in each case as soon as practicable meeting the obligations set out in section 6.4. 6.3. A list of Subprocessors that are processing Sub-Processors associated with Dubsado can be located here: https:// ▇▇▇.▇▇▇▇▇▇▇.▇▇▇/▇▇▇▇▇▇▇-▇▇▇▇▇▇▇-▇▇▇▇▇▇ 6.3.1. Dubsado will promptly inform Customer Personal Data, attached as Annex 3. SentinelOne shall provide Customer prior written notice of the appointment of any new Subprocessor, including details regarding the changing of the Processing to be undertaken by the SubprocessorSub-processors; and 6.3.2. If, if upon receiving that notice and within thirty (30) days of receipt of that noticea reasonable time, Customer notifies SentinelOne in writing informs Dubsado of any objections to sub-processing: 6.3.2.1. Dubsado to the proposed appointmentbest of their ability, and further provides commercially will make reasonable justifications changes to such objections based on valid concerns regarding such proposed Subprocessor’s business practices relating to avoid the use of personal data protection, then (i) SentinelOne shall work with Customer in good faith to address Customer’s objections regarding the new Subprocessorsaid Sub-processor; and (ii) where Customer’s concerns and 6.3.2.2. If a change cannot be resolved within thirty (30) days from SentinelOne's receipt made in a reasonable amount of Customer's time after receiving customer notice, notwithstanding anything in Customer may terminate the Principal Agreement, Customer may, by providing SentinelOne with a written notice to with immediate effect, terminate the Agreement and SentinelOne shall refund to Customer all prepaid Fees for the Solutions attributable to the Subscription Term (as outlined in the applicable Purchase Order) following the termination of these Termsnotice. 5.2 6.4. With respect to each SubprocessorSub-processor, SentinelOne Dubsado or the relevant Dubsado Affiliate shall: 5.2.1 6.4.1. before the Subprocessor Sub-processor first Processes Customer Personal DataData (or, where relevant, in accordance with section 6.2), carry out adequate due diligence to ensure that the Subprocessor Sub-processor is capable of providing the level of protection for Customer Personal Data required by the Principal Agreement; 5.2.2 6.4.2. ensure that the arrangement between on the one hand (a) SentinelOneDubsado, or (b) the relevant Dubsado Affiliate, or (c) the relevant intermediate SubprocessorSub-processor; and on the other hand, hand the SubprocessorSub-processor, is governed by a written contract including terms which offer at least the same level of protection for Customer Personal Data as those set out in this Addendum and meet the requirements of Article article 28(3) of the GDPR;; and 5.2.3 if 6.4.3. If that arrangement involves a Restricted Transfer, ensure that the Standard Contractual Clauses are at all relevant times incorporated into the agreement between on the one hand hand (a) SentinelOneDubsado, or (b) the relevant intermediate Subprocessor; and on the other hand the SubprocessorDubsado Affiliate, or before the Subprocessor first Processes Customer Personal Data procure that it enters into an agreement incorporating the Standard Contractual Clauses with the Customer. and 5.2.4 provide to Customer for review such copies of the Contracted Processors' agreements with Subprocessors (which may be redacted to remove confidential commercial information not relevant to the requirements of this Addendum) as Customer may request from time to time. 5.3 SentinelOne shall ensure that each Subprocessor performs its obligations under sections 2.1, 3, 4, 6.1, 7.2, 8 and 10.1, as they apply to Processing of Customer Personal Data carried out by that Subprocessor, as if it were party to this Addendum in place of SentinelOne.or

Appears in 1 contract

Sources: Data Processing Agreement

Subprocessing. 5.1 Customer 6.1. Each Company Group Member authorises SentinelOne Vendor and each Vendor Affiliate to appoint (and permit each Subprocessor appointed in accordance with this section 5 6 to appoint) Subprocessors in accordance with this section 5 6 and any restrictions in the Service Agreement. 6.2. SentinelOne Vendor and each Vendor Affiliate may continue to use those Subprocessors already engaged by Vendor or any Vendor Affiliate as at the date of this Addendum, subject to Vendor and each Vendor Affiliate in each case as soon as practicable meeting the obligations set out in section 6.4. 6.3. Vendor shall make available to Customer the current list of Subprocessors that are processing Customer Personal Data, attached as Annex 3. SentinelOne shall provide Customer give Company prior written notice of the appointment of any new Subprocessor, including full details of the Processing to be undertaken by the Subprocessor. If, within thirty (30) 30 days of receipt of that notice, Customer Company notifies SentinelOne Vendor in writing of any objections (on reasonable grounds) to the proposed appointment, and further provides commercially reasonable justifications to such objections based on valid concerns regarding such proposed Subprocessor’s business practices relating to data protection, then (i) SentinelOne : 6.3.1. Vendor shall work with Customer Company in good faith to address Customer’s objections regarding make available a commercially reasonable change in the new provision of the Services which avoids the use of that proposed Subprocessor; and (ii) and 6.3.2. where Customer’s concerns such a change cannot be resolved made within thirty (30) 30 days from SentinelOneVendor's receipt of CustomerCompany's notice, notwithstanding anything in the Service Agreement, Customer may, Company may by providing SentinelOne with a written notice to Vendor with immediate effect, effect terminate the Service Agreement and SentinelOne shall refund to Customer all prepaid Fees for the Solutions attributable to the Subscription Term (as outlined in extent that it relates to the applicable Purchase Order) following Services which require the termination use of these Termsthe proposed Subprocessor. 5.2 6.4. With respect to each Subprocessor, SentinelOne Vendor or the relevant Vendor Affiliate shall: 5.2.1 6.4.1. before the Subprocessor first Processes Customer Company Personal DataData (or, where relevant, in accordance with section 6.2), carry out adequate due diligence to ensure that the Subprocessor is capable of providing the level of protection for Customer Company Personal Data required by the Service Agreement; 5.2.2 6.4.2. ensure that the arrangement between on the one hand (a) SentinelOneVendor, or (b) the relevant Vendor Affiliate, or (c) the relevant intermediate Subprocessor; and on the other hand, hand the Subprocessor, is governed by a written contract including terms which offer at least the same level of protection for Customer Company Personal Data as those set out in this Addendum and meet the requirements of Article article 28(3) of the GDPR; 5.2.3 6.4.3. if that arrangement involves a Restricted Transfer, ensure that the Standard Contractual Clauses are at all relevant times incorporated into the agreement between on the one hand hand (a) SentinelOneVendor, or (b) the relevant Vendor Affiliate, or (c) the relevant intermediate Subprocessor; and on the other hand the Subprocessor, or before the Subprocessor first Processes Customer Company Personal Data procure that it enters into an agreement incorporating the Standard Contractual Clauses with the Customer. relevant Company Group Member(s) (and Company shall procure that each Company Affiliate party to any such Standard Contractual Clauses co-operates with their population and execution); and 5.2.4 6.4.4. provide to Customer Company for review such copies of the Contracted Processors' agreements with Subprocessors (which may be redacted to remove confidential commercial information not relevant to the requirements of this Addendum) as Customer Company may request from time to time. 5.3 SentinelOne 6.5. Vendor and each Vendor Affiliate shall ensure that each Subprocessor performs its the obligations under sections 2.1, 33.1, 4, 6.15, 7.27.1, 8 8.2, 9 and 10.111.1, as they apply to Processing of Customer Company Personal Data carried out by that Subprocessor, as if it were party to this Addendum in place of SentinelOneVendor.

Appears in 1 contract

Sources: Data Processing Addendum

Subprocessing. 5.1 Customer 6.1. Each Company Group Member authorises SentinelOne Vendor and each Vendor A liate to appoint (and permit each Subprocessor appointed in accordance with this section 5 6 to appoint) Subprocessors in accordance with this section 5 6 and any restrictions in the Principal Agreement. 6.2. SentinelOne Vendor and each Vendor A liate may continue to use those Subprocessors already engaged by Vendor or any Vendor A liate as at the date of this Addendum, subject to Vendor and each Vendor A liate in each case as soon as practicable meeting the obligations set out in section 6.4. 6.3. Vendor shall make available to Customer the current list of Subprocessors that are processing Customer Personal Data, attached as Annex 3. SentinelOne shall provide Customer give Company prior written notice of the appointment of any new Subprocessor, including full details of the Processing to be undertaken by the Subprocessor. If, within thirty (30) days one month of receipt of that notice, Customer Company notifies SentinelOne Vendor in writing of any objections (on reasonable grounds) to the proposed appointment, and further provides commercially reasonable justifications to such objections based on valid concerns regarding such proposed Subprocessor’s business practices relating to data protection, then (i) SentinelOne : 6.3.1. [Vendor shall work with Customer Company in good faith to address Customer’s objections regarding make available a commercially reasonable change in the new provision of the Services which avoids the use of that proposed Subprocessor; and (ii) and 6.3.2. where Customer’s concerns such a change cannot be resolved made within thirty (30) days 3 months from SentinelOneVendor's receipt of CustomerCompany's notice, notwithstanding anything in the Principal Agreement, Customer may, Company may by providing SentinelOne with a written notice to Vendor with immediate effect, e ect terminate the Principal Agreement and SentinelOne shall refund to Customer all prepaid Fees for the Solutions attributable to the Subscription Term (as outlined in extent that it relates to the applicable Purchase Order) following Services which require the termination use of these Termsthe proposed Subprocessor.] 5.2 6.4. With respect to each Subprocessor, SentinelOne Vendor or the relevant Vendor A liate shall: 5.2.1 6.4.1. before the Subprocessor first Processes Customer Company Personal DataData (or, where relevant, in accordance with section 6.2), carry out adequate due diligence to ensure that the Subprocessor is capable of providing the level of protection for Customer Company Personal Data required by the Principal Agreement; 5.2.2 6.4.2. ensure that the arrangement between on the one hand (a) SentinelOneVendor, or (b) the relevant Vendor A liate, or (c) the relevant intermediate Subprocessor; and on the other hand, hand the Subprocessor, is governed by a written contract including terms which offer o er at least the same level of protection for Customer Company Personal Data as those set out in this Addendum and meet the requirements of Article article 28(3) of the GDPR; 5.2.3 6.4.3. if that arrangement involves a Restricted Transfer, ensure that the Standard Contractual Clauses are at all relevant times incorporated into the agreement between on the one hand hand (a) SentinelOneVendor, or (b) the relevant Vendor A liate, or (c) the relevant intermediate Subprocessor; and on the other hand the Subprocessor, or before the Subprocessor first Processes Customer Company Personal Data procure that it enters into an agreement incorporating the Standard Contractual Clauses with the Customer. relevant Company Group Member(s) (and Company shall procure that each Company A liate party to any such Standard Contractual Clauses co-operates with their population and execution); and 5.2.4 6.4.4. provide to Customer Company for review such copies of the Contracted Processors' agreements with Subprocessors (which may be redacted to remove confidential commercial information not relevant to the requirements of this Addendum) as Customer Company may request from time to time. 5.3 SentinelOne 6.5. Vendor and each Vendor A liate shall ensure that each Subprocessor performs its the obligations under sections 2.1, 33.1, 4, 6.15, 7.27.1, 8 8.2, 9 and 10.111.1, as they apply to Processing of Customer Company Personal Data carried out by that Subprocessor, as if it were party to this Addendum in place of SentinelOneVendor.

Appears in 1 contract

Sources: Data Protection Addendum

Subprocessing. 5.1 Subject to the requirements of this Section, Customer authorises SentinelOne generally authorizes TaskRay to appoint (engage Subprocessors that TaskRay considers reasonably appropriate for the Processing of Customer Personal Data under this Addendum. A list of TaskRay’s Subprocessors, including their functions and permit each Subprocessor appointed locations, is available at ▇▇▇▇▇://▇▇▇.▇▇▇▇▇▇▇.▇▇▇/dpa-subprocessors and may be updated by TaskRay from time to time in accordance with this section 5 Section. TaskRay will notify Customer of the addition or replacement of any Subprocessor at least ten (10) days prior to appoint) Subprocessors in accordance with this section 5 and any restrictions in the Agreementsuch engagement. SentinelOne shall make available Customer may object to Customer the current list of Subprocessors that are processing Customer Personal Data, attached as Annex 3. SentinelOne shall provide Customer prior such changes on reasonable data protection grounds by providing TaskRay written notice of such objection within the appointment of any new Subprocessor, including details of the Processing to be undertaken by the Subprocessor. If, within thirty aforementioned ten (3010) days of receipt of that noticeperiod. Upon receiving such an objection, Customer notifies SentinelOne in writing of any objections to the proposed appointment, where practicable and further provides at TaskRay’s sole discretion TaskRay will use commercially reasonable justifications to such objections based on valid concerns regarding such proposed efforts to: (a) seek an alternative Subprocessor’s business practices relating to data protection, then ; (ib) SentinelOne shall work with Customer in good faith to address Customer’s objections regarding make available a commercially reasonable change in the provision of the Service which avoids the use of that proposed Subprocessor; or (c) take corrective steps requested by Customer in its objection and proceed to use the new Subprocessor; and (ii) where Customer’s concerns . If TaskRay informs Customer that such change or corrective steps cannot be resolved within thirty (30) days from SentinelOne's receipt of Customer's notice, notwithstanding anything in the Agreementmade, Customer may, as its sole and exclusive remedy available under this Section, terminate the relevant portion of the Agreement involving the relevant aspect of the Service that requires the use of the proposed Subprocessor by providing SentinelOne with a written notice to TaskRay. When engaging any Subprocessor, TaskRay will enter into a written contract with immediate effect, terminate such Subprocessor containing data protection obligations not less protective than those imposed upon TaskRay by this Addendum. TaskRay shall be liable for the acts and omissions of the Subprocessor to the extent TaskRay would be liable under the Agreement and SentinelOne shall refund to Customer all prepaid Fees for the Solutions attributable to the Subscription Term (as outlined in the applicable Purchase Order) following the termination of these Terms. 5.2 With respect to each Subprocessor, SentinelOne shall: 5.2.1 before the Subprocessor first Processes Customer Personal Data, carry out adequate due diligence to ensure that the Subprocessor is capable of providing the level of protection for Customer Personal Data required by the Agreement; 5.2.2 ensure that the arrangement between on the one hand (a) SentinelOne, or (b) the relevant intermediate Subprocessor; and on the other hand, the Subprocessor, is governed by a written contract including terms which offer at least the same level of protection for Customer Personal Data as those set out in this Addendum and meet the requirements of Article 28(3) of the GDPR; 5.2.3 if that arrangement involves a Restricted Transfer, ensure that the Standard Contractual Clauses are at all relevant times incorporated into the agreement between on the one hand (a) SentinelOne, or (b) the relevant intermediate Subprocessor; and on the other hand the Subprocessor, or before the Subprocessor first Processes Customer Personal Data procure that it enters into an agreement incorporating the Standard Contractual Clauses with the Customer. and 5.2.4 provide to Customer for review such copies of the Contracted Processors' agreements with Subprocessors (which may be redacted to remove confidential commercial information not relevant to the requirements of this Addendum) as Customer may request from time to time. 5.3 SentinelOne shall ensure that each Subprocessor performs its obligations under sections 2.1, 3, 4, 6.1, 7.2, 8 and 10.1, as they apply to Processing of Customer Personal Data carried out by that Subprocessor, as if it were party to this Addendum in place of SentinelOne.

Appears in 1 contract

Sources: Data Processing Addendum

Subprocessing. 5.1 Customer Each Company Group Member authorises SentinelOne Vendor to appoint (and permit each Subprocessor appointed in accordance with this section 5 to appoint) Subprocessors in accordance with this section 5 and any restrictions in the Principal Agreement. SentinelOne . 5.2 Vendor may continue to use those Subprocessors already engaged by Vendor as of the date of this Addendum, subject to Vendor in each case as soon as practicable meeting the obligations set out in section 5.4. 5.3 Vendor shall make available to Customer the current list of Subprocessors that are processing Customer Personal Data, attached as Annex 3. SentinelOne shall provide Customer give Company prior written notice of the appointment of any new Subprocessor, including full details of the Processing to be undertaken by the Subprocessor. If, within thirty (30) days one week of receipt of that notice, Customer Company notifies SentinelOne Vendor in writing of any objections (on reasonable grounds) to the proposed appointment, and further provides commercially : Vendor shall not appoint (or disclose any Company Personal Data to) that proposed Subprocessor until reasonable justifications to such objections based on valid concerns regarding such proposed Subprocessor’s business practices relating to data protection, then (i) SentinelOne shall work with Customer in good faith steps have been taken to address Customer’s the objections regarding the new Subprocessor; raised by any Company Group Member and (ii) where Customer’s concerns cannot be resolved within thirty (30) days from SentinelOne's receipt of Customer's notice, notwithstanding anything in the Agreement, Customer may, by providing SentinelOne Company has been provided with a reasonable written notice to with immediate effect, terminate explanation of the Agreement and SentinelOne shall refund to Customer all prepaid Fees for the Solutions attributable to the Subscription Term (as outlined in the applicable Purchase Order) following the termination of these Termssteps taken. 5.2 5.4 With respect to each Subprocessor, SentinelOne Vendor shall: 5.2.1 5.4.1 before the Subprocessor first Processes Customer Company Personal DataData (or, where relevant, in accordance with section 5.2), carry out adequate due diligence to ensure that the Subprocessor is capable of providing the level of protection for Customer Company Personal Data required by the Principal Agreement; 5.2.2 5.4.2 ensure that the arrangement between on the one hand (a) SentinelOneVendor, or (b) the relevant intermediate Subprocessor; and on the other hand, hand the Subprocessor, is governed by a written contract including terms which offer at least the same level of protection for Customer Company Personal Data as those set out in this Addendum and meet the requirements of Article article 28(3) of the GDPR; 5.2.3 5.4.3 if that arrangement involves a Restricted Transfer, ensure that the Standard Contractual Clauses are at all relevant times incorporated into the agreement between on the one hand hand (a) SentinelOneVendor, or (b) the relevant intermediate Subprocessor; and on the other hand the Subprocessor, or before the Subprocessor first Processes Customer Company Personal Data procure that it enters into an agreement incorporating the Standard Contractual Clauses with the Customer. relevant Company Group Member(s) (and Company shall procure that each Company Affiliate party to any such Standard Contractual Clauses co-operates with their population and execution); and 5.2.4 5.4.4 provide to Customer Company for review such copies of the Contracted Processors' agreements with Subprocessors (which may be redacted to remove confidential commercial information not relevant to the requirements of this Addendum) as Customer Company may request from time to time. 5.3 SentinelOne 5.5 Vendor shall ensure that each Subprocessor performs its the obligations under sections 2.13.1, 3, 4, 6.1, 7.2, 8 and 10.1, as they apply to Processing of Customer Company Personal Data carried out by that Subprocessor, as if it were party to this Addendum in place of SentinelOneVendor.

Appears in 1 contract

Sources: Data Protection Addendum

Subprocessing. 5.1 (a) Customer authorises SentinelOne acknowledges and agrees that JazzHR may engage Subprocessors in connection with the provision of the Services. A list of approved Subprocessors as of the Effective Date of this Addendum is located at ▇▇▇▇▇://▇▇▇.▇▇▇▇▇▇.▇▇▇/subprocessor­list (the “Subprocessor List”). Customer may subscribe to appoint receive update alerts when changes are made to the Subprocessor List. (and permit b) JazzHR will enter into a written agreement with each Subprocessor appointed containing data protection obligations, to the extent practicable, no less protective than those in accordance with this section 5 Addendum or as may otherwise be required by applicable Data Protection Laws and Regulations. JazzHR agrees to appoint) Subprocessors in accordance with this section 5 and any restrictions in be responsible for the acts or omissions of each such Subprocessor to the same extent as JazzHR would be liable if performing the services of such Sub­processor under the terms of the Agreement. (c) JazzHR will inform Customer of any new Subprocessor engaged during the term of the Agreement by updating the Subprocessor List. SentinelOne shall make available to If Customer the current list of Subprocessors reasonably believes that are processing Customer Personal Data, attached as Annex 3. SentinelOne shall provide Customer prior written notice of the appointment of any a new SubprocessorSubprocessor will have a material adverse effect on JazzHR’s ability to comply with applicable Data Protection Laws and Regulations as a Processor, including details of the Processing to be undertaken by the Subprocessor. Ifthen Customer must notify JazzHR in writing, within thirty (30) 30 days following the update to the Subprocessor List, of its reasonable basis for such belief. Upon receipt of that Customer’s written notice, Customer notifies SentinelOne in writing of any objections to the proposed appointmentand JazzHR will work together without unreasonable delay on an alternative arrangement. If a mutually­agreed alternative arrangement is not found, and further provides commercially reasonable justifications to such objections based on valid concerns regarding such proposed Subprocessor’s business practices relating to data protectionCustomer has a termination right under applicable Data Protection Laws and Regulations, then those Services that cannot be provided without the use of the new Subprocessor may be terminated by Customer without penalty. (d) Notices and Consents: (i) SentinelOne General: Customer shall work comply with Customer in good faith all applicable Data Protection Laws and Regulations, including: (a) providing all required notices and appropriate disclosures to address all Data Subjects regarding Customer’s, and JazzHR’s, Processing and transfer of Personal Data; and (b) obtaining all necessary rights and valid consents from Data Subjects to permit Processing by JazzHR for the purposes of fulfilling JazzHR’s objections regarding obligations, or as otherwise permitted, under the new Subprocessor; and Agreement. (ii) where Sensitive Data: Customer’s concerns cannot use of the Services in connection with the distribution of Customer Data and/or Processing of sensitive Customer Data of a Data Subject (such as racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, or an individual’s genetic data, biometric data, health data, or data regarding sex life or sexual orientation) must be resolved within thirty (30) days in compliance with all applicable Data Protection Laws and Regulations, including obtaining express consent from SentinelOne's receipt of Customer's notice, notwithstanding anything in the Agreement, Customer may, by providing SentinelOne with a written notice to with immediate effect, terminate the Agreement and SentinelOne shall refund to Customer all prepaid Fees for the Solutions attributable to the Subscription Term (as outlined in the applicable Purchase Order) following the termination of these Terms. 5.2 With respect to each Subprocessor, SentinelOne shall: 5.2.1 before the Subprocessor first Processes Customer Personal Data, carry out adequate due diligence to ensure that the Subprocessor is capable of providing the level of protection for Customer Data Subjects whose Personal Data required by the Agreement; 5.2.2 ensure that the arrangement between on the one hand (a) SentinelOne, or (b) the relevant intermediate Subprocessor; and on the other hand, the Subprocessor, is governed by a written contract including terms which offer at least the same level of protection provided to JazzHR for Customer Personal Data as those set out in this Addendum and meet the requirements of Article 28(3) of the GDPR; 5.2.3 if that arrangement involves a Restricted Transfer, ensure that the Standard Contractual Clauses are at all relevant times incorporated into the agreement between on the one hand (a) SentinelOne, or (b) the relevant intermediate Subprocessor; and on the other hand the Subprocessor, or before the Subprocessor first Processes Customer Personal Data procure that it enters into an agreement incorporating the Standard Contractual Clauses with the Customer. and 5.2.4 provide to Customer for review such copies of the Contracted Processors' agreements with Subprocessors (which may be redacted to remove confidential commercial information not relevant to the requirements of this Addendum) as Customer may request from time to timeProcessing. 5.3 SentinelOne shall ensure that each Subprocessor performs its obligations under sections 2.1, 3, 4, 6.1, 7.2, 8 and 10.1, as they apply to Processing of Customer Personal Data carried out by that Subprocessor, as if it were party to this Addendum in place of SentinelOne.

Appears in 1 contract

Sources: Data Processing Addendum

Subprocessing. 5.1 7.1 Accredible may engage third parties to perform the agreed Processing activities under this Accredible DPA (“Subcontractor”) subject to the requirements pursuant to this Sec.7. 7.2 Any Subcontractor with access to Personal Data covered by the GDPR shall be obliged before initiating the Processing, to commit itself in writing for the benefit of Customer authorises SentinelOne and its Affiliates to appoint comply with the same data protection obligations as the ones under this Accredible DPA or legal act within the meaning of Art. 28 para 3, 4 and 6 GDPR unless explicitly agreed otherwise. The agreement with the Subcontractor must provide at least the level of data protection required by this Accredible DPA. Where the Subcontractor fails to fulfil its data protection obligations, Accredible shall remain fully liable to Customer for the performance of the Subcontractorʼs obligations (the corresponding Clause 11 SCC shall remain unaffected). 7.3 Any Subcontractor must in particular agree to comply with the agreed technical and permit each Subprocessor appointed organizational security measures in accordance with this section 5 to appoint) Subprocessors in accordance Sec. 5.5.2 and 5.5.3 herein and provide Accredible, with this section 5 a list of the implemented technical and any restrictions in the Agreement. SentinelOne shall make organizational measures, which upon request by Customer will also be made available to Customer. Subcontractorʼs measures may differ from the ones agreed between Customer the current list of Subprocessors that are processing Customer Personal Data, attached as Annex 3. SentinelOne and Accredible but shall provide Customer prior written notice of the appointment of any new Subprocessor, including details of the Processing to be undertaken by the Subprocessor. If, within thirty (30) days of receipt of that notice, Customer notifies SentinelOne in writing of any objections to the proposed appointment, and further provides commercially reasonable justifications to such objections based on valid concerns regarding such proposed Subprocessor’s business practices relating to data protection, then (i) SentinelOne shall work with Customer in good faith to address Customer’s objections regarding the new Subprocessor; and (ii) where Customer’s concerns cannot be resolved within thirty (30) days from SentinelOne's receipt of Customer's notice, notwithstanding anything in the Agreement, Customer may, by providing SentinelOne with a written notice to with immediate effect, terminate the Agreement and SentinelOne shall refund to Customer all prepaid Fees for the Solutions attributable to the Subscription Term (as outlined in the applicable Purchase Order) following the termination of these Terms. 5.2 With respect to each Subprocessor, SentinelOne shall: 5.2.1 before the Subprocessor first Processes Customer Personal Data, carry out adequate due diligence to ensure that the Subprocessor is capable of providing fall below the level of data security as provided by the measures of Accredible. 7.4 Where a Subcontractor refuses to be bound by the same data protection for obligations as the ones under this Accredible DPA, Customer may consent thereto, whereby such consent shall not be unreasonably withheld. 7.5 Accredible will inform Customer in Text Form of any intended engagement of a Subcontractor with access to Personal Data required covered by the Agreement; 5.2.2 ensure GDPR. Alternatively, Accredible may provide a website or provide another notice that the arrangement between on the one hand (a) SentinelOne, or (b) the relevant intermediate Subprocessor; and on the other hand, the Subprocessor, is governed by a written contract including terms which offer at least the same level of protection for Customer lists all Subcontractors to access to Personal Data of its Customer covered by the GDPR as those set out in this Addendum and meet well as the requirements of Article 28(3limited or ancillary services they provide. At least two (2) of the GDPR; 5.2.3 if that arrangement involves a Restricted Transfer, ensure that the Standard Contractual Clauses are at all relevant times incorporated into the agreement between on the one hand (a) SentinelOne, or (b) the relevant intermediate Subprocessor; and on the other hand the Subprocessor, or weeks before the Subprocessor first Processes Customer Personal Data procure that it enters into an agreement incorporating the Standard Contractual Clauses with the Customer. and 5.2.4 provide authorizing any new Subcontractor to Customer for review such copies of the Contracted Processors' agreements with Subprocessors (which may be redacted to remove confidential commercial information not relevant to the requirements of this Addendum) as Customer may request from time to time. 5.3 SentinelOne shall ensure that each Subprocessor performs its obligations under sections 2.1, 3, 4, 6.1, 7.2, 8 and 10.1, as they apply to Processing of Customer Personal Data carried out by that Subprocessor, as if it were party to this Addendum in place of SentinelOne.access such

Appears in 1 contract

Sources: Data Protection Amendment Agreement

Subprocessing. 5.1 Customer authorises SentinelOne 7.1 Subject to appoint Section 7.3, the Service Provider is hereby authorized to engage other Processors in relation to the Processing of Company Personal Data under this DPA (and permit each Subprocessor appointed "SubProcessor") in accordance with this section 5 and to appoint) Subprocessors the extent permitted by Data Protection Laws. As of the date hereof, the Service Provider engages exclusively the SubProcessors listed in accordance Exhibit C which the Service Provider may continue to use, provided that the obligations set out in Section 7.2 are met. The Service Provider shall at all times and without being so requested provide the Company with this section 5 and any restrictions in the Agreement. SentinelOne shall make available an up to Customer the current date list of Subprocessors that are processing Customer Personal DataSubProcessors, attached as Annex 3. SentinelOne shall provide Customer prior written notice detailing company name, address, contact details, the specific area of Processing operations outsourced and the location of the appointment of any new Subprocessor, including details of the Processing to be undertaken by the Subprocessor. If, within thirty (30) days of receipt of that notice, Customer notifies SentinelOne in writing of any objections to the proposed appointment, and further provides commercially reasonable justifications to such objections based on valid concerns regarding such proposed Subprocessor’s business practices relating to data protection, then (i) SentinelOne shall work with Customer in good faith to address Customer’s objections regarding the new Subprocessor; and (ii) where Customer’s concerns cannot be resolved within thirty (30) days from SentinelOne's receipt of Customer's notice, notwithstanding anything in the Agreement, Customer may, by providing SentinelOne with a written notice to with immediate effect, terminate the Agreement and SentinelOne shall refund to Customer all prepaid Fees for the Solutions attributable to the Subscription Term (as outlined in the applicable Purchase Order) following the termination of these TermsProcessing. 5.2 7.2 With respect to each SubprocessorSubProcessor, SentinelOne shall:the Service Provider shall:‌ 5.2.1 (a) before any Company Personal Data is transferred to the Subprocessor first Processes Customer Personal DataSubProcessor, carry out adequate due diligence to ensure that the Subprocessor SubProcessor is capable of (i) providing the level of protection for Customer Company Personal Data required by this DPA, the AgreementPrincipal Agreement and Data Protection Laws and (ii) complying with the Standard Contractual Clauses adopted by the EU Commission or any other safeguards applied in relation to a Cross Border Transfer (as defined in Section 8.1 below) and, where required or appropriate, has taken supplementary effective measures to ensure an essentially equivalent level of protection; 5.2.2 (b) enter into a written agreement with the SubProcessor which imposes the same obligations on the SubProcessor in relation to the protection of Company Personal Data as are imposed on the Service Provider under this DPA; (c) upon written request provide the Company with the Sub-contracting agreement and any other documentation reasonably requested by the Company (it being understood that the Service Provider shall be permitted to redact any confidential commercial terms which are and not required by the Company to assess compliance of the Service Provider with its obligations under this DPA); and (d) conduct regular audits as required to ensure that the arrangement between SubProcessor complies with the Data Security Standards and its other contractual obligations and shall promptly notify the Company in writing in accordance with Section 10 of any breach of a SubProcessor's obligations. 7.3 Service Provider shall give Company prior written notice of the intended engagement of any new SubProcessor, including full details of the Processing to be undertaken by the SubProcessor. If, within three weeks of receipt of that notice, the Company notifies Service Provider in writing of any objections on reasonable grounds to the one hand proposed appointment, Service Provider shall not appoint (or disclose any Company Personal Data to) that proposed SubProcessor until reasonable steps have been taken to address the objections raised by the Company.‌ 7.4 In case of non-compliance of any SubProcessor with its contractual obligations, (a) SentinelOne, the Service Provider shall remain liable to the Company for any damages caused by such non-compliance and shall indemnify and hold harmless the Company against any claims or damages in connection with or resulting from the engagement of the SubProcessor; and (b) the relevant intermediate Subprocessor; and on Company shall be entitled to withdraw its consent to the other hand, engagement of such SubProcessor in which case the Subprocessor, is governed by a written contract including terms which offer at least Service Provider shall promptly stop engaging such SubProcessor in connection with the same level of protection for Customer Personal Data as those set out in this Addendum and meet the requirements of Article 28(3) of the GDPR; 5.2.3 if that arrangement involves a Restricted Transfer, Processing Services. The Service Provider shall ensure that the Standard Contractual Clauses are at all relevant times incorporated into the agreement between on the one hand (a) SentinelOne, or (b) the relevant intermediate Subprocessor; SubProcessor promptly and on the other hand the Subprocessor, or before the Subprocessor first Processes Customer Personal Data procure that it enters into an agreement incorporating the Standard Contractual Clauses fully complies with the Customer. and 5.2.4 provide to Customer for review such copies of the Contracted Processors' agreements with Subprocessors (which may be redacted to remove confidential commercial information not relevant to the requirements of this Addendum) as Customer may request from time to time. 5.3 SentinelOne shall ensure that each Subprocessor performs its obligations under sections 2.1, 3, 4, 6.1, 7.2, 8 and 10.1, as they apply to Processing of Customer Personal Data carried out by that Subprocessor, as if it were party to this Addendum in place of SentinelOneSection 12.

Appears in 1 contract

Sources: Construction Management Agreement

Subprocessing. 5.1 Customer authorises SentinelOne acknowledges and agrees that Netlify may utilize the authorized Sub-processors set forth in Schedule 2. 5.2 Netlify shall by email inform the Customer of any changes concerning the addition or replacement of sub-processors, at least ten (10) business days prior to appoint (and permit each Subprocessor appointed in accordance with this section 5 to appoint) Subprocessors in accordance with this section 5 and any restrictions in such change(s), thereby giving the Agreement. SentinelOne shall make available to Customer the current list of Subprocessors that are processing opportunity to object to such changes. Customer Personal Data, attached as Annex 3. SentinelOne shall provide Customer prior written notice of the appointment of any new Subprocessor, including details of the Processing may object in writing to be undertaken by the Subprocessor. If, Netlify’s intended change concerning Netlify’s Sub-processors within thirty five (305) business days of receipt of that such notice, . 5.3 If it is not possible for Netlify and Customer notifies SentinelOne in writing of any objections to resolve the proposed appointment, and further provides commercially issue within a reasonable justifications to such objections based on valid concerns regarding such proposed Subprocessor’s business practices relating to data protection, then (i) SentinelOne shall work with Customer in time despite both parties’ good faith to address Customer’s objections regarding the new Subprocessor; and (ii) where Customer’s concerns cannot be resolved within thirty (30) days from SentinelOne's receipt of Customer's noticeefforts, notwithstanding anything in the Principal Agreement, Customer may, by providing SentinelOne with may suspend or terminate the Principal Agreement to the extent that it relates to the Services which require the use of the proposed Sub-processor. 5.4 Netlify will enter into a written notice to agreement with immediate effect, terminate the Agreement and SentinelOne shall refund to Customer all prepaid Fees for the Solutions attributable to the Subscription Term (as outlined in the applicable Purchase Order) following the termination of these Terms. 5.2 With respect to each Subprocessor, SentinelOne shall: 5.2.1 before the Subprocessor first Processes Customer Personal Data, carry out adequate due diligence to ensure that the Subprocessor is capable of providing the level of protection for Customer Personal Data required by the Agreement; 5.2.2 ensure that the arrangement between on the one hand (a) SentinelOne, or (b) the relevant intermediate Subprocessor; and on the other hand, the Subprocessor, is governed by a written contract including Sub-processor containing terms which offer at least the same level of protection for Customer Personal Data as those set out in this Addendum DPA, imposing in particular that each Sub-processor provides sufficient guarantees to implement appropriate technical and organisational measures in such a manner that the Processing will meet the requirements of Article 28(3the GDPR. 5.5 Netlify shall remain fully liable to Customer for the performance of its Sub-processor's obligations to the same extent Netlify would be liable if performing the Services directly under the terms of this DPA. 5.6 If Customer and Netlify have entered into Standard Contractual Clauses as described in Section 11 (Transfer mechanisms for data transfers), (i) the above authorizations will constitute Customer’s prior written consent to the subcontracting by Netlify of the processing of Personal Data if such consent is required under the Standard Contractual Clauses, and (ii) the parties agree that the copies of the agreements with Sub-processors that must be provided by Netlify to Customer pursuant to Clause 5(j) of the GDPR; 5.2.3 if that arrangement involves a Restricted Transfer, ensure that the Standard Contractual Clauses are at all relevant times incorporated into the agreement between on the one hand (a) SentinelOnemay have commercial information, or (b) the relevant intermediate Subprocessor; and on the other hand the Subprocessor, or before the Subprocessor first Processes Customer Personal Data procure that it enters into an agreement incorporating information unrelated to the Standard Contractual Clauses with the Customer. and 5.2.4 provide to Customer for review or their equivalent, removed by Netlify beforehand, and that such copies of will be provided by the Contracted Processors' agreements with Subprocessors (which may be redacted to remove confidential commercial information not relevant to the requirements of this Addendum) as Customer may Netlify only upon request from time to timeby Customer. 5.3 SentinelOne shall ensure that each Subprocessor performs its obligations under sections 2.1, 3, 4, 6.1, 7.2, 8 and 10.1, as they apply to Processing of Customer Personal Data carried out by that Subprocessor, as if it were party to this Addendum in place of SentinelOne.

Appears in 1 contract

Sources: Data Processing Agreement

Subprocessing. 5.1 Customer 11.1 The Controller authorises SentinelOne the Processor to appoint (and permit permits each Subprocessor appointed in accordance with this section 5 clause 11 to appoint) Subprocessors strictly in accordance with this section 5 clause 11 and any restrictions in the Principal Agreement. SentinelOne . 11.2 The Processor may continue to use those Subprocessors already engaged by the Processor as at the date of this Agreement, subject to the Processor as soon as practicable meeting the obligations set out in clause 11.4. 11.3 The Processor shall make available to Customer give the current list of Subprocessors that are processing Customer Personal Data, attached as Annex 3. SentinelOne shall provide Customer Controller prior written notice of the appointment of any new Subprocessor, including full details of the Processing to be undertaken by the Subprocessor. If, within thirty seven (307) days of receipt of that notice, Customer the Controller notifies SentinelOne the Processor in writing of any objections to the proposed appointment, and further provides commercially reasonable justifications to such objections based on valid concerns regarding such the Processor shall not appoint (nor disclose any Controller Personal Data to) the proposed Subprocessor’s business practices relating to data protection, then (i) SentinelOne shall work Subprocessor except with Customer in good faith to address Customer’s objections regarding the new Subprocessor; and (ii) where Customer’s concerns cannot be resolved within thirty (30) days from SentinelOne's receipt prior written consent of Customer's notice, notwithstanding anything in the Agreement, Customer may, by providing SentinelOne with a written notice to with immediate effect, terminate the Agreement and SentinelOne shall refund to Customer all prepaid Fees for the Solutions attributable to the Subscription Term (as outlined in the applicable Purchase Order) following the termination of these TermsController. 5.2 11.4 With respect to each Subprocessor, SentinelOne the Processor shall: 5.2.1 11.4.1 before the Subprocessor first Processes Customer processes Controller Personal Data, carry out adequate due diligence in accordance with Good Industry Practice to ensure that the Subprocessor is capable of providing the level of protection for Customer the Controller Personal Data required by the Principal Agreement; 5.2.2 11.4.2 ensure that the arrangement between on the one hand (a) SentinelOne, or (b) the relevant intermediate Subprocessor; Processor and on the other hand, the Subprocessor, Subprocessor is governed by a written contract including terms which offer at least the same level of protection for Customer the Controller Personal Data as those set out in this Addendum Agreement and meet the requirements of Article article 28(3) of the GDPR; 5.2.3 if that arrangement involves a Restricted Transfer, ensure that the Standard Contractual Clauses are at all relevant times incorporated into the agreement between on the one hand (a) SentinelOne, or (b) the relevant intermediate Subprocessor; and on the other hand the Subprocessor, or before the Subprocessor first Processes Customer Personal Data procure that it enters into an agreement incorporating the Standard Contractual Clauses with the Customer. and 5.2.4 11.4.3 provide to Customer the Controller for review such copies of the Contracted Processors' agreements with Subprocessors (which may be redacted to remove confidential commercial information not relevant to the requirements of this AddendumAgreement) as Customer the Controller may request from time to time. 5.3 SentinelOne 11.5 The Processor shall ensure that each Subprocessor performs its the applicable obligations under sections 2.1, 3, 4, 6.1, 7.2, 8 and 10.1this Agreement, as they apply to Processing processing of Customer Controller Personal Data carried out by that Subprocessor, as if it were party to this Addendum Agreement in place of SentinelOnethe Processor. 11.6 The Processor shall be liable for any failure of the Subprocessor to comply with its obligations pursuant to clause 11.5, and shall fully indemnify and keep fully indemnified the Controller against any and all actions, costs, claims, demands, damages, expenses (including legal fees), liabilities, losses and proceedings in connection with any failure of the Subprocessor to comply with its obligations pursuant to clause 11.5.

Appears in 1 contract

Sources: Booking Agreement

Subprocessing. 5.1 To the extent required under Applicable Laws, Customer authorises SentinelOne authorizes CrowdStrike to appoint (and permit each Subprocessor appointed in accordance with this section 5 to appoint) Subprocessors in accordance with this section 5 and any restrictions in the Agreement. SentinelOne shall make available . 5.2 CrowdStrike may continue to use those Subprocessors already engaged as of the date of this DPA specified in Exhibit E, subject to CrowdStrike in each case meeting the obligations set out in section 5.5. 5.3 Customer the current agrees to CrowdStrike maintaining and updating its list of Subprocessors that are processing online, for the Falcon Platform as outlined in Exhibit E. 5.4 CrowdStrike shall provide notice of a proposed new Subprocessor to the Customer, at least 30 days prior to CrowdStrike’s use of the new Subprocessor to Process Customer Personal Data, attached as Annex 3through the applicable CrowdStrike Offering or platform, where Customer may elect to subscribe to such notices. SentinelOne shall provide Customers may sign up for email Subprocessor notifications at ▇▇▇▇▇://▇▇▇.▇▇▇▇▇▇▇▇▇▇▇.▇▇▇/subprocessor-notification/. During the notice period, Customer prior may object to a change in Subprocessor in writing and CrowdStrike may, in its sole discretion, attempt to resolve Customer’s objection, including providing the Offerings without use of the proposed Subprocessor. If (a) CrowdStrike provides Customer written notice of the appointment of any new Subprocessorthat it will not pursue an alternative, including details of the Processing to be undertaken by the Subprocessor. If, within thirty or (30b) days of receipt of that notice, Customer notifies SentinelOne in writing of any objections to the proposed appointment, and further provides commercially reasonable justifications to such objections based on valid concerns regarding such proposed Subprocessor’s business practices relating to data protection, then (i) SentinelOne shall work with Customer in good faith to address Customer’s objections regarding the new Subprocessor; and (ii) where Customer’s concerns an alternative cannot be resolved made available by CrowdStrike to Customer within thirty (30) 90 days from SentinelOne's receipt of Customer's noticeCustomer providing notice of its objection, then in either case, and notwithstanding anything to the contrary in the AgreementAgreement or order, Customer may, by providing SentinelOne with a written notice to with immediate effect, may terminate the Agreement and SentinelOne shall refund to Customer all prepaid Fees for the Solutions attributable or order to the Subscription Term (as outlined in extent that it relates to the applicable Purchase Order) following Offerings which require the termination use of these Termsthe proposed Subprocessor. 5.2 5.5 With respect to each Subprocessor, SentinelOne to the extent required under Applicable Laws, CrowdStrike shall: 5.2.1 before 5.5.1 Before the Subprocessor first Processes Customer Personal DataData (or, where relevant, in accordance with section 5.2), carry out adequate due diligence to ensure that the Subprocessor is capable of providing the level of protection for Customer Personal Data required by Applicable Laws, this DPA and the Agreement; 5.2.2 ensure 5.5.2 Ensure that the arrangement between on the one hand (a) SentinelOne, or (b) the relevant intermediate Subprocessor; CrowdStrike and on the other hand, the Subprocessor, Subprocessor is governed by a written contract including terms which offer at least offers substantially the same level of protection for Customer Personal Data as those set out required by this DPA and Applicable Laws, including Customer’s ability to protect the rights of Data Subjects in this Addendum and meet the requirements of Article 28(3) of the GDPRevent CrowdStrike is insolvent, liquidated or otherwise ceases to exist; 5.2.3 if that arrangement 5.5.3 Apply an adequacy mechanism recognized by Customer’s Supervisory Authority as ensuring an adequate level of data protection under Applicable Laws where Subprocessor’s Processing of Customer Personal Data involves a Restricted Transfer, ensure that the Standard Contractual Clauses are at all relevant times incorporated into the agreement between on the one hand; (a) SentinelOne, or (b) the relevant intermediate Subprocessor; and on the other hand the Subprocessor, or before the Subprocessor first Processes Customer Personal Data procure that it enters into an agreement incorporating the Standard Contractual Clauses with the Customer. and 5.2.4 provide to Customer for review such 5.5.4 Maintain copies of the Contracted Processors' agreements with Subprocessors (which may be redacted to remove confidential commercial information not relevant to the requirements of this Addendum) and make these available as Customer may request from time to time.. To the extent necessary to protect Confidential Information, CrowdStrike may redact the copies prior to sharing with Customer; and 5.3 SentinelOne shall ensure that each Subprocessor performs its 5.5.5 Notify Customer of Subprocessor’s relevant failure to comply with obligations under sections 2.1, 3, 4, 6.1, 7.2, 8 and 10.1, as they apply to Processing of Customer Personal Data carried set out by that Subprocessor, as if it were party to Applicable Laws and this Addendum in place DPA where CrowdStrike has received notice of SentinelOnesuch.

Appears in 1 contract

Sources: Data Protection Agreement

Subprocessing. 5.1 Customer ‌ 6.1 Each Company Group Member authorises SentinelOne Vendor and each Vendor Affiliate to appoint (and permit each Subprocessor appointed in accordance with this section 5 6 to appoint) Subprocessors in accordance with this section 5 6 and any restrictions in the Principal Agreement. SentinelOne . 6.2 Vendor and each Vendor Affiliate may continue to use those Subprocessors already engaged by Vendor or any Vendor Affiliate as at the date of this Addendum, subject to Vendor and each Vendor Affiliate in each case as soon as practicable meeting the obligations set out in section 6.4.‌ 6.3 Vendor shall make available to Customer the current list of Subprocessors that are processing Customer Personal Data, attached as Annex 3. SentinelOne shall provide Customer give Company prior written notice of the appointment of any new Subprocessor, including full details of the Processing to be undertaken by the Subprocessor. If, within thirty [ 30 (30thirty) calendar days ] of receipt of that notice, Customer Company notifies SentinelOne Vendor in writing of any objections (on reasonable grounds) to the proposed appointment, and further provides commercially reasonable justifications to such objections based on valid concerns regarding such proposed Subprocessor’s business practices relating to data protection, then (i) SentinelOne : 6.3.1 [Vendor shall work with Customer Company in good faith to address Customer’s objections regarding make available a commercially reasonable change in the new provision of the Services which avoids the use of that proposed Subprocessor; and (ii) and 6.3.2 where Customer’s concerns such a change cannot be resolved made within thirty [ 30 (30thirty) calendar days ] from SentinelOneVendor's receipt of CustomerCompany's notice, notwithstanding anything in the Principal Agreement, Customer may, Company may by providing SentinelOne with a written notice to Vendor with immediate effect, effect terminate the Principal Agreement and SentinelOne shall refund to Customer all prepaid Fees for the Solutions attributable to the Subscription Term (as outlined in extent that it relates to the applicable Purchase Order) following Services which require the termination use of these Termsthe proposed Subprocessor.] 5.2 6.4 With respect to each Subprocessor, SentinelOne shall:Vendor or the relevant Vendor Affiliate shall:‌ 5.2.1 6.4.1 before the Subprocessor first Processes Customer Company Personal DataData (or, where relevant, in accordance with section 6.2) , carry out adequate due diligence to ensure that the Subprocessor is capable of providing the level of protection for Customer Company Personal Data required by the Principal Agreement; 5.2.2 6.4.2 ensure that the arrangement between on the one hand (a) SentinelOneVendor, or (b) the relevant Vendor Affiliate, or (c) the relevant intermediate Subprocessor; and on the other hand, hand the Subprocessor, is governed by a written contract including terms which offer at least the same level of protection for Customer Company Personal Data as those set out in this Addendum and meet the requirements of Article article 28(3) of the GDPR; 5.2.3 6.4.3 if that arrangement involves a Restricted Transfer, ensure that the Standard Contractual Clauses are at all relevant times incorporated into the agreement between on the one hand hand (a) SentinelOneVendor, or (b) the relevant Vendor Affiliate, or (c) the relevant intermediate Subprocessor; and on the other hand the Subprocessor, or before the Subprocessor first Processes Customer Company Personal Data procure that it enters into an agreement incorporating the Standard Contractual Clauses with the Customer. andrelevant Company Group Member(s) (and Company shall procure that each Company Affiliate party to any such Standard Contractual Clauses co-operates with their population and execution); and‌ 5.2.4 6.4.4 provide to Customer Company for review such copies of o f the Contracted Processors' agreements with Subprocessors (which may be redacted to remove confidential commercial information not relevant to the requirements of this Addendum) as Customer Company may request from time to time. 5.3 SentinelOne 6.5 Vendor and each Vendor Affiliate shall ensure that each Subprocessor performs its the obligations under sections 2.1, 33.1, 4, 6.15, 7.27.1, 8 8.2, 9 and 10.111.1, as they apply to Processing of Customer Company Personal Data carried out by that Subprocessor, as if it were party to this Addendum in place of SentinelOne.Vendor.‌

Appears in 1 contract

Sources: Data Protection Addendum

Subprocessing. 5.1 Customer 11.1. The Data Controller authorises SentinelOne the Data Processor to appoint [(and permit each Subprocessor appointed in accordance with this section 5 11 to appoint) )] Subprocessors in accordance with this section 5 11 and any restrictions in the AgreementTerms and Conditions or Privacy Policy. 11.2. SentinelOne The Data Processor may continue to use those Subprocessors already engaged by the Data Processor as at the date of this Addendum and listed in Annex 2, subject to the Data Processor in each case as soon as practicable meeting the obligations set out in section 11.4. 11.3. The Data Processor shall make available to Customer give the current list of Subprocessors that are processing Customer Personal Data, attached as Annex 3. SentinelOne shall provide Customer Data Controller prior written notice of the appointment of any new Subprocessor, including full details of the Processing to be undertaken by the Subprocessor. If, within thirty 30 (30thirty) calendar days of receipt of that notice, Customer the Data Controller notifies SentinelOne the Data Processor in writing of any objections (on reasonable grounds) to the proposed appointment, and further provides commercially reasonable justifications to such objections based on valid concerns regarding such proposed Subprocessor’s business practices relating to data protection, then : (ia) SentinelOne the Data Processor shall work with Customer the Data Controller in good faith to address Customer’s objections regarding make available a commercially reasonable change in the new provision of the Services which avoids the use of that proposed Subprocessor; and and (iib) where Customer’s concerns such a change cannot be resolved made within thirty 30 (30thirty) calendar days from SentinelOnethe Data Processor's receipt of Customerthe Data Cotroller's noticenotice (or such longer period as the parties may agree in writing), notwithstanding anything in the Agreement, Customer may, Terms and Conditions or Privacy Policy the Data Controller may by providing SentinelOne with a written notice to the Data Processor with immediate effect, effect terminate the Agreement Terms and SentinelOne shall refund to Customer all prepaid Fees for the Solutions attributable Conditions to the Subscription Term (as outlined in extent that it relates to the applicable Purchase Order) following Services which require the termination use of these Termsthe proposed Subprocessor. 5.2 11.4. With respect to each Subprocessor, SentinelOne the Data Processor shall: 5.2.1 before the Subprocessor first Processes Customer Personal Data, (a) carry out adequate due diligence on each Subprocessor to ensure that the Subprocessor it is capable of providing the level of protection for Customer the Personal Data as is required by this Addendum including without limitation sufficient guarantees to implement appropriate technical and organisational measures in such a manner that Processing will meet the Agreementrequirements of GDPR or equivalent provisions of any Data Protection Law and this Addendum; 5.2.2 ensure that the arrangement between on the one hand (a) SentinelOne, or (b) include terms in the relevant intermediate Subprocessor; contract between the Data Processor and on the other hand, the Subprocessor, is governed by a written contract including terms each Subprocessor which offer at least the same level of protection for Customer the Personal Data as those set out in this Addendum and meet Upon request, the Data Processor shall provide a copy of its agreements with Subprocessors to the Data Controller (which may be redacted to remove confidential commercial information not relevant to the requirements of Article 28(3) of the GDPRthis Addendum); 5.2.3 (c) if that the arrangement involves a Restricted Transfer, ensure that the Standard Contractual Clauses are at all relevant times incorporated into the agreement between on the one hand (a) SentinelOne, or (b) the relevant intermediate Subprocessor; Data Processor and on the other hand the Subprocessor, or before the Subprocessor first Processes Customer the Personal Data Data, procure that it enters into an agreement incorporating the Standard Contractual Clauses with the Customer. Data Controller; and 5.2.4 provide (d) remain fully liable to Customer the Data Controller for review such copies any failure by each Subprocessor to fulfil its obligations in relation to the Processing of the Contracted Processors' agreements with Subprocessors (which may be redacted to remove confidential commercial information not relevant to the requirements of this Addendum) as Customer may request from time to timePersonal Data. 5.3 SentinelOne shall ensure that each Subprocessor performs its obligations under sections 2.1, 3, 4, 6.1, 7.2, 8 and 10.1, as they apply to Processing of Customer Personal Data carried out by that Subprocessor, as if it were party to this Addendum in place of SentinelOne.

Appears in 1 contract

Sources: Agreement for the Provision of Box Office & on Line Ticketing Services

Subprocessing. 5.1 5.1. Customer authorises SentinelOne authorizes Zip to appoint (and permit each Subprocessor appointed in accordance with this section 5 to appoint) Subprocessors in accordance with this section 5 section. 5.2. Information about Subprocessors, including their functions and any restrictions locations, as of the Addendum Effective Date is set forth in Attachment 3 (as may be updated by Provider from time to time) or such other website address as Provider may provide to customer from time to time (the Agreement“Subprocessor Site”). SentinelOne Customer acknowledges and agrees that Zip may utilize the Subprocessors listed in Attachment 3 and/or on the Subprocessor Site as of the Addendum Effective Date. 5.3. Zip shall make available to Customer the current list of Subprocessors that are processing Customer Personal Data, attached as Annex 3. SentinelOne shall provide give Customer prior written notice of the appointment of any proposed new SubprocessorSubprocessor after the Addendum Effective Date by updating the Subprocessor Site or other written means, including reasonable details of the Processing to be undertaken by the Subprocessor. If Customer does not object to such change of Subprocessors within fourteen (14) days of receipt of that notice, Customer shall be deemed to have consented to such change. If, within thirty fourteen (3014) days of receipt of that notice, Customer notifies SentinelOne Zip in writing of any objections (on reasonable grounds relating to the protection of Customer Personal Data) to the proposed appointment, and further provides : (a) Zip shall use reasonable efforts to make available a commercially reasonable justifications to such objections based on valid concerns regarding such change in the provision of the Services, which avoids the use of that proposed Subprocessor’s business practices relating to data protection, then (i) SentinelOne shall work with Customer in good faith to address Customer’s objections regarding the new Subprocessor; and (iib) where Customer’s concerns such a change cannot be resolved within thirty made and failing an amicable resolution between the parties (30) days from SentinelOne's receipt of Customer's notice, notwithstanding anything each acting reasonably and in the Agreementgood faith), Customer may, may by providing SentinelOne with a written notice to Zip with immediate effect, effect terminate the Agreement and SentinelOne shall refund to Customer all prepaid Fees for the Solutions attributable to the Subscription Term (extent that it relates to the Services which require the use of the proposed Subprocessor as outlined in the applicable Purchase Order) following the termination of these Termsits sole and exclusive remedy. 5.2 5.4. With respect to each Subprocessor, SentinelOne shall: 5.2.1 before the Subprocessor first Processes Customer Personal Data, carry out adequate due diligence to ensure that the Subprocessor is capable of providing the level of protection for Customer Personal Data required by the Agreement; 5.2.2 ensure that the arrangement between on the one hand (a) SentinelOne, or (b) the relevant intermediate Subprocessor; and on the other hand, the Subprocessor, is governed by Zip shall enter into a written contract including terms which offer at least are substantially similar regarding the same level protection of protection for Customer Personal Data as those set out in this Addendum and meet the requirements of Article 28(3) of the GDPR;Data Processing Addendum. 5.2.3 if that arrangement involves a Restricted Transfer, ensure that the Standard Contractual Clauses are 5.5. Zip shall at all relevant times incorporated into the agreement between on the one hand (a) SentinelOne, or (b) the relevant intermediate Subprocessor; and on the other hand the Subprocessor, or before the Subprocessor first Processes Customer Personal Data procure that it enters into an agreement incorporating the Standard Contractual Clauses with the Customer. and 5.2.4 provide remain liable to Customer for review such copies of the Contracted Processors' agreements with Subprocessors (which may be redacted to remove confidential commercial information not relevant to the requirements of this Addendum) as Customer may request from time to time. 5.3 SentinelOne shall ensure that each Subprocessor performs its obligations under sections 2.1, 3, 4, 6.1, 7.2, 8 Subprocessors’ acts and 10.1, as they apply to Processing omissions in respect of Customer Personal Data carried out by that Subprocessor, as to the same extent Zip would be liable if it were party to performing such Processing directly under the terms of this Addendum in place of SentinelOneData Processing Addendum.

Appears in 1 contract

Sources: Data Processing Addendum

Subprocessing. 5.1 3.1 Customer authorises SentinelOne grants Amperity a general authorization to appoint (and permit each Subprocessor appointed in accordance with this section 5 to appoint) Subprocessors in accordance with this section 5 and any restrictions in subcontract the Agreement. SentinelOne shall make available to Customer the current list Processing of Subprocessors that are processing Customer Personal Data, attached as Annex 3. SentinelOne shall provide Customer prior written notice of the appointment of any new Data to a Subprocessor, including details of the Processing to be undertaken by the Subprocessor. If, within thirty those Subprocessors listed in Amperity's website at ▇▇▇▇▇://▇▇▇▇.▇▇▇▇▇▇▇▇.▇▇▇/support/subcontractors.html (30) days of receipt of that notice, Customer notifies SentinelOne in writing of any objections to the proposed appointment, and further provides commercially reasonable justifications to such objections based on valid concerns regarding such proposed Subprocessor’s business practices relating to data protection, then (i) SentinelOne shall work with Customer in good faith to address Customer’s objections regarding the new Subprocessor; and (ii) where Customer’s concerns cannot be resolved within thirty (30) days from SentinelOne's receipt of Customer's notice, notwithstanding anything in the Agreement, Customer may, by providing SentinelOne with a written notice to with immediate effect, terminate the Agreement and SentinelOne shall refund to Customer all prepaid Fees for the Solutions attributable to the Subscription Term (as outlined in the applicable Purchase Order) following the termination of these Terms"Subprocessor List"). 5.2 With respect to each Subprocessor, SentinelOne shall3.2 Amperity will: 5.2.1 before the Subprocessor first Processes Customer Personal Data, carry out adequate due diligence to ensure that the Subprocessor is capable of providing the level of protection for Customer Personal Data required by the Agreement; 5.2.2 ensure that the arrangement between on the one hand (a) SentinelOne, or (b) the relevant intermediate Subprocessor; and on the other hand, the Subprocessor, is governed by enter into a written contract including agreement with each Subprocessor containing data protection terms which offer that provide at least the same level of protection for Customer Personal Data as those set out contained in this Addendum and meet DPA, to the requirements of Article 28(3) extent applicable to the nature of the GDPR;services provided by each Subprocessor; and 5.2.3 if that arrangement involves a Restricted Transfer, ensure that the Standard Contractual Clauses are at all relevant times incorporated into the agreement between on the one hand (a) SentinelOne, or (b) the relevant intermediate Subprocessor; and on the other hand the Subprocessor, or before the Subprocessor first Processes Customer Personal Data procure that it enters into an agreement incorporating the Standard Contractual Clauses with the Customer. and 5.2.4 provide remain responsible to Customer for review such copies any acts or omissions of the Contracted Processors' agreements with Subprocessors (which may be redacted Subprocessor that cause Amperity to remove confidential commercial information not relevant to the requirements breach any of this Addendum) as Customer may request from time to time. 5.3 SentinelOne shall ensure that each Subprocessor performs its obligations under sections 2.1this DPA. 3.3 Prior to the addition of any new Subprocessor, 3Amperity shall provide notice to Customer not less than ten (10) calendar days prior to the date on which the Subprocessor shall commence Processing Customer Personal Data. Amperity provides a subscription form along with the Subprocessor list for Customers to subscribe to receive automatic notifications of changes to the Subprocessor List. Customer acknowledges and agrees that it shall subscribe to Amperity's notice mechanism provided in the Subprocessor List to receive the notices and that Amperity will only provide the corresponding notice to the email address provided in the subscription form. 3.4 Customer may object to Amperity's appointment of any new or replacement Subprocessor promptly in writing within ten (10) calendar days of receipt of the automatic notice in accordance with 3.3 above and on reasonable grounds related to Subprocessor's ability to comply with Applicable Data Protection Law. In such case, 4the Parties shall discuss Customer´s concerns in good faith with a view to achieving a commercially reasonable resolution. If the Parties cannot reach such resolution, 6.1Amperity shall, 7.2at its sole discretion, 8 either not appoint the Subprocessor at issue, or permit Customer to suspend or terminate the applicable Order Form and/or the Agreement without liability to either Party. In the event Customer exercises its right of termination under this Section 3.4, Amperity will refund to Customer a pro rata share of any prepaid unused fees for the remaining and 10.1unexpired portion of the applicable Subscription Term from the date of termination, as they apply to Processing of Customer Personal Data carried out by that Subprocessor, as if it were party to this Addendum in place of SentinelOnethe Customer’s exclusive remedy.

Appears in 1 contract

Sources: Data Processing Agreement

Subprocessing. 5.1 Customer 6.1 Each Company Group Member authorises SentinelOne 17hats and each 17hats Affiliate to appoint (and permit each Subprocessor appointed in accordance with this section 5 6 to appoint) Subprocessors in accordance with this section 5 6 and any restrictions in the Principal Agreement. SentinelOne shall make available . 6.2 17hats and each 17hats Affiliate may continue to Customer use those Subprocessors already engaged by 17hats or any 17hats Affiliate as at the current date of this Addendum, subject to 17hats and each 17hats Affiliate in each case as soon as practicable meeting the obligations set out in section 6.4. 6.3 17hats maintains a list of Subprocessors that are processing Customer Personal Dataon its Privacy Policy web page, attached as Annex 3. SentinelOne shall provide Customer prior written notice which can be found at ▇▇▇▇▇://▇▇▇.▇▇▇▇▇▇.▇▇▇/privacy-policy, and which includes an email address for subscribing to email notifications on the occasion of the appointment of any new SubprocessorSubprocessors 6.3.1 Company Group Member shall subscribe, including details of and if Company Group Member subscribes, 17hats shall provide, via email to the Processing email address provided, send information on any proposed Subprocessor appointments at least seven (7) calendar days prior to be undertaken by the Subprocessor. such update. 6.3.2 If, within thirty three (303) calendar days of receipt of that notice, Customer Company Group Member notifies SentinelOne 17hats in writing of any objections (on reasonable grounds) to the proposed appointment, and further provides commercially reasonable justifications to such objections based on valid concerns regarding such proposed Subprocessor’s business practices relating to data protection, then (i) SentinelOne ; 6.3.2.1 17hats shall work with Customer Company in good faith to address Customer’s objections regarding make available a commercially reasonable change in the new provision of the Services which avoids the use of that proposed Subprocessor; and (ii) and 6.3.2.2 where Customer’s concerns such a change cannot be resolved made within thirty (30) calendar days from SentinelOne's 17hats' receipt of CustomerCompany's notice, notwithstanding anything in the Principal Agreement, Customer may, Company may by providing SentinelOne with a written notice to 17hats with immediate effect, effect terminate the Principal Agreement and SentinelOne shall refund to Customer all prepaid Fees for the Solutions attributable to the Subscription Term (as outlined in extent that it relates to the applicable Purchase Order) following Services which require the termination use of these Termsthe proposed Subprocessor. 5.2 6.4 With respect to each Subprocessor, SentinelOne 17hats or the relevant 17hats Affiliate shall: 5.2.1 6.4.1 before the Subprocessor first Processes Customer Company Personal DataData (or, where relevant, in accordance with section 6.2), carry out adequate due diligence to ensure that the Subprocessor is capable of providing the level of protection for Customer Company Personal Data required by the Principal Agreement; 5.2.2 6.4.2 ensure that the arrangement between on the one hand (a) SentinelOne17hats, or (b) the relevant 17hats Affiliate, or (c) the relevant intermediate Subprocessor; and on the other hand, hand the Subprocessor, is governed by a written contract including terms which offer at least the same level of protection for Customer Company Personal Data as those set out in this Addendum and meet the requirements of Article article 28(3) of the GDPR; 5.2.3 6.4.3 if that arrangement involves a Restricted Transfer, ensure that the Standard Contractual Clauses are at all relevant times incorporated into the agreement between on the one hand hand (a) SentinelOne17hats, or (b) the relevant 17hats Affiliate, or (c) the relevant intermediate Subprocessor; and on the other hand the Subprocessor, or before the Subprocessor first Processes Customer Company Personal Data procure that it enters into an agreement incorporating the Standard Contractual Clauses with the Customer. relevant Company Group Member(s) (and Company shall procure that each Company Affiliate party to any such Standard Contractual Clauses co-operates with their population and execution); and 5.2.4 6.4.4 provide to Customer Company for review such copies of the Contracted Processors' agreements with Subprocessors (which may be redacted to remove confidential commercial information not relevant to the requirements of this Addendum) as Customer Company may request from time to time. 5.3 SentinelOne 6.5 17hats and each 17hats Affiliate shall ensure that each Subprocessor performs its the obligations under sections 2.1, 33.1, 4, 6.15, 7.27.1, 8 8.2, 9 and 10.111.1, as they apply to Processing of Customer Company Personal Data carried out by that Subprocessor, as if it were party to this Addendum in place of SentinelOne17hats.

Appears in 1 contract

Sources: Data Protection Addendum

Subprocessing. 5.1 6.1 Dynatrace shall maintain an up-to-date list at ▇▇▇▇▇://▇▇▇.▇▇▇▇▇▇▇▇▇.▇▇▇/company/legal/customers/ of all Subprocessors used in the provision of Services who may Process (a) Customer authorises SentinelOne Data (which may contain Customer Personal Data), or (b) other Customer Personal Data received by Dynatrace from Customer through the Services under the Agreement (“Subprocessor List”). At the Effective Date, Customer gives its general authorization to Dynatrace to appoint (and permit each the Subprocessors on the Subprocessor appointed List to assist it in providing the Services by Processing Customer Personal Data in accordance with this section 5 DPA and for purposes of Clause 11 of the Model Clauses. 6.2 Customer shall ensure any Subprocessors appointed to appoint) Subprocessors assist in accordance providing the Services enter into a written agreement with Dynatrace which imposes on the Subprocessor obligations which are substantially the same as those imposed on Dynatrace under this section 5 and DPA. 6.3 Dynatrace remains liable for any restrictions in breach of this DPA that is caused by an act, error or omission of its Subprocessor to the Agreement. SentinelOne extent Dynatrace would have been liable for such act, error or omission had it been caused by Dynatrace. 6.4 Prior to the addition or change of any Subprocessors, Dynatrace shall make available provide notice to Customer Customer, which may include by updating the current list of Subprocessors that are Subprocessor List on the website listed above, not less than 10 days prior to the date on which the Subprocessor shall commence processing Customer Personal Data. Dynatrace will make available a means by which Customer may subscribe to receive notifications of changes to the Subprocessor List (which may include without limitation the provision of an RSS feed). 6.5 If Customer objects to the processing of Customer Personal Data by any newly appointed Subprocessor as described in Section 6.4 (on reasonable grounds), attached as Annex 3it shall inform Dynatrace in writing within 7 days after notice has been provided by Dynatrace setting out the specific reasons for its objection. SentinelOne Customer shall provide Customer prior written notice of the appointment not unreasonably object to any intended change of any new Subprocessor, including details of Subprocessors. In the Processing to be undertaken by the Subprocessor. If, event Customer objects within thirty (30) days of receipt of that notice, Customer notifies SentinelOne in writing of any objections to the proposed appointment, and further provides commercially such timeframe on reasonable justifications to such objections based on valid concerns regarding such proposed Subprocessor’s business practices grounds relating to data protectionprotection of Customer Personal Data, then (i) SentinelOne the parties shall work with Customer together in good faith to address Customer’s reasonable objections regarding and thereafter proceed to use the new Subprocessor; and (ii) where Customer’s concerns Subprocessor to perform such Processing. If agreement cannot be resolved reached between the parties to use the new Subprocessor within thirty one month of the objection, Dynatrace shall either, at Dynatrace’s option: (30a) days from SentinelOne's receipt of Customer's notice, notwithstanding anything in the Agreement, Customer may, by providing SentinelOne with a written notice to with immediate effect, terminate the Agreement and SentinelOne shall refund to Customer all prepaid Fees for the Solutions attributable to the Subscription Term (as outlined in the applicable Purchase Order) following the termination of these Terms. 5.2 With respect to each Subprocessor, SentinelOne shall: 5.2.1 before instruct the Subprocessor first Processes not to process Customer Personal Data, carry out adequate due diligence which may result in a Service feature being suspended and unavailable to ensure that the Subprocessor is capable of providing the level of protection for Customer Personal Data required by the Agreement; 5.2.2 ensure that the arrangement between on the one hand (a) SentinelOne, Customer; or (b) allow Customer to terminate this DPA and the relevant intermediate Subprocessor; Agreement on three months’ notice, and on Dynatrace will promptly refund a prorated portion of any prepaid fees for the other handperiod after such suspension or termination date. If no objection is received by Dynatrace within the time period specified above, Customer shall be deemed to have approved the Subprocessor, is governed by a written contract including terms which offer at least the same level of protection for Customer Personal Data as those set out in this Addendum and meet the requirements of Article 28(3) use of the GDPR; 5.2.3 if that arrangement involves a Restricted Transfer, ensure that the Standard Contractual Clauses are at all relevant times incorporated into the agreement between on the one hand (a) SentinelOne, or (b) the relevant intermediate new Subprocessor; and on the other hand the Subprocessor, or before the Subprocessor first Processes Customer Personal Data procure that it enters into an agreement incorporating the Standard Contractual Clauses with the Customer. and 5.2.4 provide to Customer for review such copies of the Contracted Processors' agreements with Subprocessors (which may be redacted to remove confidential commercial information not relevant to the requirements of this Addendum) as Customer may request from time to time. 5.3 SentinelOne shall ensure that each Subprocessor performs its obligations under sections 2.1, 3, 4, 6.1, 7.2, 8 and 10.1, as they apply to Processing of Customer Personal Data carried out by that Subprocessor, as if it were party to this Addendum in place of SentinelOne.

Appears in 1 contract

Sources: Data Processing Agreement

Subprocessing. 5.1 The Subprocessors currently engaged by Docmosis and authorized by Customer are listed in Annex 3. The Customer generally authorises SentinelOne Docmosis to appoint (and permit each Subprocessor appointed in accordance with this section 5 to appoint) Subprocessors in accordance with this section 5 and any restrictions in the Agreement. SentinelOne . 5.2 Docmosis may continue to use those Subprocessors already engaged by Docmosis as at the date of this Addendum, subject to Docmosis in each case as soon as practicable meeting the obligations set out in section 5.4. 5.3 Docmosis shall make available to Customer the current list of Subprocessors that are processing Customer Personal Data, attached as Annex 3. SentinelOne shall provide give Customer prior written notice of the appointment of any new Subprocessor, including full details of the Processing to be undertaken by the Subprocessor. If, within thirty (30) 30 days of receipt of that notice, Customer notifies SentinelOne Docmosis in writing of any objections (on reasonable grounds) to the proposed appointment, and further provides commercially reasonable justifications to such objections based on valid concerns regarding such proposed Subprocessor’s business practices relating to data protection, then (i) SentinelOne shall work with appointment Customer in good faith to address Customer’s objections regarding the new Subprocessor; and (ii) where Customer’s concerns cannot be resolved within thirty (30) days from SentinelOne's receipt of Customer's notice, notwithstanding anything in the Agreement, Customer may, may by providing SentinelOne with a written notice to Docmosis with immediate effect, effect terminate the Agreement and SentinelOne shall refund to Customer all prepaid Fees for the Solutions attributable to the Subscription Term (as outlined in extent that it relates to the applicable Purchase Order) following Services which require the use of the proposed Subprocessor. This termination of these Termsright is Customer’s sole and exclusive remedy if Customer objects to any new Third Party Subprocessor. 5.2 5.4 With respect to each Subprocessor, SentinelOne Docmosis shall: 5.2.1 5.4.1 before the Subprocessor first Processes Customer Personal DataData (or, where relevant, in accordance with section 5.2), carry out adequate due diligence to ensure that the Subprocessor is capable of providing the level of protection for Customer Personal Data required by the Agreement; 5.2.2 5.4.2 ensure that the arrangement between on the one hand (a) SentinelOneDocmosis, or (b) the relevant intermediate Subprocessor; and on the other hand, hand the Subprocessor, is governed by a written contract including terms which offer at least the same level of protection for Customer Personal Data as those set out in this Addendum and meet the requirements of Article article 28(3) of the GDPR; 5.2.3 5.4.3 if that arrangement involves a Restricted Transfer, ensure that the Standard Contractual Clauses are at all relevant times incorporated into the agreement between on the one hand hand (a) SentinelOneDocmosis, or (b) the relevant intermediate Subprocessor; and on the other hand the Subprocessor, or before the Subprocessor first Processes Customer Personal Data procure that it enters into an agreement incorporating the Standard Contractual Clauses with the Customer. ; and 5.2.4 5.4.4 provide to Customer for review such copies of the Contracted Processors' agreements with Subprocessors (which may be redacted to remove confidential commercial information not relevant to the requirements of this Addendum) as Customer may request from time to time. 5.3 SentinelOne 5.5 Docmosis shall ensure that each Subprocessor performs its the obligations under sections 2.1, 3, 4, 6.1, 7.2, 8 and 10.1, as they apply to Processing of Customer Personal Data carried out by that Subprocessor, as if it were party to this Addendum in place of SentinelOneDocmosis.

Appears in 1 contract

Sources: Data Processing Addendum

Subprocessing. 5.1 Customer authorises SentinelOne to appoint (and permit each Subprocessor appointed in accordance with this section 5 to appoint) Subprocessors in accordance with this section 5 and any restrictions in the Agreement. SentinelOne 6.1 Vendor shall make available to Customer the current list of Subprocessors that are processing Customer Personal Data, attached as Annex 3. SentinelOne shall provide Customer give Company prior written notice of the appointment of any new Subprocessor, including full details of the Processing to be undertaken by the Subprocessor. If, within thirty (30) 15 days of receipt of that notice, Customer Company notifies SentinelOne Vendor in writing of any objections (on reasonable grounds) to the proposed appointment, and further provides commercially reasonable justifications to such objections based on valid concerns regarding such : Neither Vendor nor any Vendor Affiliate shall appoint (nor disclose any Company Personal Data to) the proposed Subprocessor’s business practices relating to data protection, then (i) SentinelOne shall work Subprocessor except with Customer in good faith to address Customer’s objections regarding the new Subprocessor; and (ii) where Customer’s concerns cannot be resolved within thirty (30) days from SentinelOne's receipt prior written consent of Customer's notice, notwithstanding anything in the Agreement, Customer may, by providing SentinelOne with a written notice to with immediate effect, terminate the Agreement and SentinelOne shall refund to Customer all prepaid Fees for the Solutions attributable to the Subscription Term (as outlined in the applicable Purchase Order) following the termination of these TermsCompany. 5.2 6.2 With respect to each Subprocessor, SentinelOne Vendor or the relevant Vendor Affiliate shall: 5.2.1 6.2.1 before the Subprocessor first Processes Customer Company Personal DataData (or, where relevant, in accordance with section 6.2), carry out adequate due diligence to ensure that the Subprocessor is capable of providing the level of protection for Customer Company Personal Data required by the Principal Agreement; 5.2.2 6.2.2 ensure that the arrangement between on the one hand (a) SentinelOneVendor, or (b) the relevant Vendor Affiliate, or (c) the relevant intermediate Subprocessor; and on the other hand, hand the Subprocessor, is governed by a written contract including terms which offer at least the same level of protection for Customer Company Personal Data as those set out in this Addendum and meet the requirements of Article article 28(3) of the GDPR; 5.2.3 6.2.3 if that arrangement involves a Restricted Transfer, ensure that the Standard Contractual Clauses are at all relevant times incorporated into the agreement between on the one hand hand (a) SentinelOneVendor, or (b) the relevant Vendor Affiliate, or (c) the relevant intermediate Subprocessor; and on the other hand the Subprocessor, or before the Subprocessor first Processes Customer Company Personal Data procure that it enters into an agreement incorporating the Standard Contractual Clauses with the Customer. relevant Company Group Member(s) (and Company shall procure that each Company Affiliate party to any such Standard Contractual Clauses co-operates with their population and execution); and 5.2.4 6.2.4 provide to Customer Company for review such copies of the Contracted Processors' agreements with Subprocessors (which may be redacted to remove confidential commercial information not relevant to the requirements of this Addendum) as Customer Company may request from time to time. 5.3 SentinelOne 6.3 Vendor and each Vendor Affiliate shall ensure that each Subprocessor performs its the obligations under sections 2.1, 33.1, 4, 6.15, 7.27.1, 8 8.2, 9 and 10.111.1, as they apply to Processing of Customer Company Personal Data carried out by that Subprocessor, as if it were party to this Addendum in place of SentinelOneVendor.

Appears in 1 contract

Sources: Data Protection Addendum

Subprocessing. 5.1 (a) Customer authorises SentinelOne acknowledges and agrees that JazzHR may engage Subprocessors in connection with the provision of the Services. A list of approved Subprocessors as of the Effective Date of this Addendum is located at ▇▇▇▇▇://▇▇▇.▇▇▇▇▇▇.▇▇▇/subprocessor-list (the “Subprocessor List”). Customer may subscribe to appoint receive update alerts when changes are made to the Subprocessor List. (and permit b) JazzHR will enter into a written agreement with each Subprocessor appointed containing data protection obligations, to the extent practicable, no less protective than those in accordance with this section 5 Addendum or as may otherwise be required by applicable Data Protection Laws and Regulations. JazzHR agrees to appoint) Subprocessors in accordance with this section 5 and any restrictions in be responsible for the acts or omissions of each such Subprocessor to the same extent as JazzHR would be liable if performing the services of such Sub-processor under the terms of the Agreement. (c) JazzHR will inform Customer of any new Subprocessor engaged during the term of the Agreement by updating the Subprocessor List. SentinelOne shall make available to If Customer the current list of Subprocessors reasonably believes that are processing Customer Personal Data, attached as Annex 3. SentinelOne shall provide Customer prior written notice of the appointment of any a new SubprocessorSubprocessor will have a material adverse effect on JazzHR’s ability to comply with applicable Data Protection Laws and Regulations as a Processor, including details of the Processing to be undertaken by the Subprocessor. Ifthen Customer must notify JazzHR in writing, within thirty (30) 30 days following the update to the Subprocessor List, of its reasonable basis for such belief. Upon receipt of that Customer’s written notice, Customer notifies SentinelOne in writing of any objections to the proposed appointmentand JazzHR will work together without unreasonable delay on an alternative arrangement. If a mutually-agreed alternative arrangement is not found, and further provides commercially reasonable justifications to such objections based on valid concerns regarding such proposed Subprocessor’s business practices relating to data protectionCustomer has a termination right under applicable Data Protection Laws and Regulations, then those Services that cannot be provided without the use of the new Subprocessor may be terminated by Customer without penalty. (d) Notices and Consents: (i) SentinelOne General: Customer shall work comply with Customer in good faith all applicable Data Protection Laws and Regulations, including: (a) providing all required notices and appropriate disclosures to address all Data Subjects regarding Customer’s objections regarding the new Subprocessor’s, and JazzHR’s, Processing and transfer of Personal Data; and (b) obtaining all necessary rights and valid consents from Data Subjects to permit Processing by JazzHR for the purposes of fulfilling JazzHR’s obligations, or as otherwise permitted, under the Agreement. (ii) where Sensitive Data: Customer’s concerns cannot use of the Services in connection with the distribution of Customer Data and/or Processing of sensitive Customer Data of a Data Subject (such as racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, or an individual’s genetic data, biometric data, health data, or data regarding sex life or sexual orientation) must be resolved within thirty (30) days in compliance with all applicable Data Protection Laws and Regulations, including obtaining express consent from SentinelOne's receipt of Customer's notice, notwithstanding anything in the Agreement, Customer may, by providing SentinelOne with a written notice to with immediate effect, terminate the Agreement and SentinelOne shall refund to Customer all prepaid Fees for the Solutions attributable to the Subscription Term (as outlined in the applicable Purchase Order) following the termination of these Terms. 5.2 With respect to each Subprocessor, SentinelOne shall: 5.2.1 before the Subprocessor first Processes Customer Personal Data, carry out adequate due diligence to ensure that the Subprocessor is capable of providing the level of protection for Customer Data Subjects whose Personal Data required by the Agreement; 5.2.2 ensure that the arrangement between on the one hand (a) SentinelOne, or (b) the relevant intermediate Subprocessor; and on the other hand, the Subprocessor, is governed by a written contract including terms which offer at least the same level of protection provided to JazzHR for Customer Personal Data as those set out in this Addendum and meet the requirements of Article 28(3) of the GDPR; 5.2.3 if that arrangement involves a Restricted Transfer, ensure that the Standard Contractual Clauses are at all relevant times incorporated into the agreement between on the one hand (a) SentinelOne, or (b) the relevant intermediate Subprocessor; and on the other hand the Subprocessor, or before the Subprocessor first Processes Customer Personal Data procure that it enters into an agreement incorporating the Standard Contractual Clauses with the Customer. and 5.2.4 provide to Customer for review such copies of the Contracted Processors' agreements with Subprocessors (which may be redacted to remove confidential commercial information not relevant to the requirements of this Addendum) as Customer may request from time to timeProcessing. 5.3 SentinelOne shall ensure that each Subprocessor performs its obligations under sections 2.1, 3, 4, 6.1, 7.2, 8 and 10.1, as they apply to Processing of Customer Personal Data carried out by that Subprocessor, as if it were party to this Addendum in place of SentinelOne.

Appears in 1 contract

Sources: Data Processing Agreement

Subprocessing. 5.1 Customer authorises SentinelOne Supplier agrees that any third- party Subprocessor it appoints shall be bound to appoint the same standard of data protection provided for by this Agreement; and that Supplier will enter into agreements accordingly with its applicable subprocessors to give appropriate effect to the requirements in this DPA Controller agrees that Supplier may use any subprocessor listed in Annex B. Notwithstanding this, Controller consents to Supplier engaging new subprocessors (and permit each Subprocessor appointed in accordance with this section 5 including the replacement of existing ones) to appoint) Subprocessors in accordance with this section 5 and any restrictions in process the Agreement. SentinelOne shall make available to Customer the current list of Subprocessors that are processing Customer Personal Data, attached as Annex 3. SentinelOne shall provide Customer provided that: (i) Supplier provides at least 30 business days prior written notice of the appointment addition or replacement of any new Subprocessor, subprocessor (including details of the Processing processing it performs or will perform), which may be given by provided details of such addition or replacement to be undertaken by the Subprocessor. If, within thirty (30) days of receipt of that notice, Customer notifies SentinelOne in writing of any objections to the proposed appointment, and further provides commercially reasonable justifications to such objections based on valid concerns regarding such proposed Subprocessor’s business practices relating to data protection, then (i) SentinelOne shall work with Customer in good faith to address Customer’s objections regarding the new SubprocessorController; and (ii) where Customer’s concerns canSupplier imposes data protection terms on any subprocessor it appoints that protect the Personal Data to the same standard provided for by this DPA. If Controller refuses to consent to Supplier's appointment of a new third-party subprocessor, which should not be resolved within thirty (30) days from SentinelOne's receipt of Customer's noticewithheld unreasonably, notwithstanding anything in then either Supplier will not appoint the subprocessor or Controller may elect to terminate the Agreement, Customer may, by providing SentinelOne with a written notice to with immediate effect, terminate provided that the Agreement Controller has substantial and SentinelOne shall refund to Customer all prepaid Fees documented reasons for the Solutions attributable objection to the Subscription Term change. Pemrosesan Lanjutan: Pemasok setuju bahwa Pemroses lanjutan pihak ketiga mana pun yang ditunjuknya harus terikat standar perlindungan data yang sama yang diatur di dalam Perjanjian ini; dan bahwa Pemasok akan mengikatkan diri ke dalam perjanjian-perjanjian sebagaimana mestinya dengan pemroses lanjutan yang berlaku untuk memberikan efek yang sesuai terhadap persyaratan dalam DPA ini, Pengendali setuju bahwa Pemasok dapat menggunakan pemroses lanjutannya sebagaimana tercantum dalam Lampiran B. Terlepas dari hal ini, Pengendali mengizinkan Pemasok melibatkan pemroses lanjutan baru (as outlined in the applicable Purchase Ordertermasuk penggantian Pemroses lanjutan yang sudah ada) following the termination of these Termsuntuk memproses Data Pribadi, dengan ketentuan bahwa: (i) Pemasok memberikan pemberitahuan penambahan atau penggantian pemroses lanjutan (termasuk rincian pemrosesan yang dilakukan atau akan dilakukan olehnya) selambat-lambatnya 30 hari kerja sebelumnya, yang dapat diberikan dengan menyediakan rincian penambahan atau penggantian tersebut kepada Pengendali; dan (ii) Pemasok menerapkan ketentuan perlindungan data kepada pemroses lanjutan yang ditunjuknya bahwa perlindungan Data Pribadi dilakukan sama seperti standar yang disediakan oleh DPA ini. Jika Pengendali menolak memberikan izin terhadap penunjukan pemroses lanjutan pihak ketiga yang baru oleh Pemasok, yang tidak boleh tidak diberikan dengan alasan yang tidak wajar, maka Pemasok tidak akan menunjuk pemroses lanjutan tersebut atau Pengendali dapat memilih mengakhiri Perjanjian, dengan ketentuan bahwa Pengendali memiliki alasan-alasan substansial dan terdokumentasi atas keberatan perubahan tersebut. 5.2 With respect to each Subprocessor, SentinelOne shall: 5.2.1 before the Subprocessor first Processes Customer Personal Data, carry out adequate due diligence to ensure that the Subprocessor is capable of providing the level of protection for Customer Personal Data required by the Agreement; 5.2.2 ensure that the arrangement between on the one hand (a) SentinelOne, or (b) the relevant intermediate Subprocessor; and on the other hand, the Subprocessor, is governed by a written contract including terms which offer at least the same level of protection for Customer Personal Data as those set out in this Addendum and meet the requirements of Article 28(3) of the GDPR; 5.2.3 if that arrangement involves a Restricted Transfer, ensure that the Standard Contractual Clauses are at all relevant times incorporated into the agreement between on the one hand (a) SentinelOne, or (b) the relevant intermediate Subprocessor; and on the other hand the Subprocessor, or before the Subprocessor first Processes Customer Personal Data procure that it enters into an agreement incorporating the Standard Contractual Clauses with the Customer. and 5.2.4 provide to Customer for review such copies of the Contracted Processors' agreements with Subprocessors (which may be redacted to remove confidential commercial information not relevant to the requirements of this Addendum) as Customer may request from time to time. 5.3 SentinelOne shall ensure that each Subprocessor performs its obligations under sections 2.1, 3, 4, 6.1, 7.2, 8 and 10.1, as they apply to Processing of Customer Personal Data carried out by that Subprocessor, as if it were party to this Addendum in place of SentinelOne.

Appears in 1 contract

Sources: Data Processor Agreement

Subprocessing. 5.1 Customer 11.1. The Data Controller authorises SentinelOne the Data Processor to appoint [(and permit each Subprocessor appointed in accordance with this section 5 11 to appoint) )] Subprocessors in accordance with this section 5 11 and any restrictions in the AgreementTerms and Conditions or Privacy Policy. 11.2. SentinelOne The Data Processor may continue to use those Subprocessors already engaged by the Data Processor as at the date of this Addendum and listed in Annex 2, subject to the Data Processor in each case as soon as practicable meeting the obligations set out in section 11.4. 11.3. The Data Processor shall make available to Customer give the current list of Subprocessors that are processing Customer Personal Data, attached as Annex 3. SentinelOne shall provide Customer Data Controller prior written notice of the appointment of any new Subprocessor, including full details of the Processing to be undertaken by the Subprocessor. If, within thirty 30 (30thirty) calendar days of receipt of that notice, Customer notifies SentinelOne the Data Controller notifies the Data Processor in writing of any objections (on reasonable grounds) to the proposed appointment, and further provides commercially reasonable justifications to such objections based on valid concerns regarding such proposed Subprocessor’s business practices relating to data protection, then : (ia) SentinelOne the Data Processor shall work with Customer the Data Controller in good faith to address Customer’s objections regarding make available a commercially reasonable change in the new provision of the Services which avoids the use of that proposed Subprocessor; and and (iib) where Customer’s concerns such a change cannot be resolved made within thirty 30 (30thirty) calendar days from SentinelOnethe Data Processor's receipt of Customerthe Data Cotroller's noticenotice (or such longer period as the parties may agree in writing), notwithstanding anything in the Agreement, Customer may, Terms and Conditions or Privacy Policy the Data Controller may by providing SentinelOne with a written notice to the Data Processor with immediate effect, effect terminate the Agreement Terms and SentinelOne shall refund to Customer all prepaid Fees for the Solutions attributable Conditions to the Subscription Term (as outlined in extent that it relates to the applicable Purchase Order) following Services which require the termination use of these Termsthe proposed Subprocessor. 5.2 11.4. With respect to each Subprocessor, SentinelOne the Data Processor shall: 5.2.1 before the Subprocessor first Processes Customer Personal Data, (a) carry out adequate due diligence on each Subprocessor to ensure that the Subprocessor it is capable of providing the level of protection for Customer the Personal Data as is required by this Addendum including without limitation sufficient guarantees to implement appropriate technical and organisational measures in such a manner that Processing will meet the Agreementrequirements of GDPR or equivalent provisions of any Data Protection Law and this Addendum; 5.2.2 ensure that the arrangement between on the one hand (a) SentinelOne, or (b) include terms in the relevant intermediate Subprocessor; contract between the Data Processor and on the other hand, the Subprocessor, is governed by a written contract including terms each Subprocessor which offer offer at least the same level of protection for Customer the Personal Data as those set out in this Addendum and meet Upon request, the Data Processor shall provide a copy of its agreements with Subprocessors to the Data Controller (which may be redacted to remove confidential commercial information not relevant to the requirements of Article 28(3) of the GDPRthis Addendum); 5.2.3 (c) if that the arrangement involves a Restricted Transfer, ensure that the Standard Contractual Clauses are at all relevant times incorporated into the agreement between on the one hand (a) SentinelOne, or (b) the relevant intermediate Subprocessor; Data Processor and on the other hand the Subprocessor, or before the Subprocessor first first Processes Customer the Personal Data Data, procure that it enters into an agreement incorporating the Standard Contractual Clauses with the Customer. Data Controller; and 5.2.4 provide (d) remain fully liable to Customer the Data Controller for review such copies any failure by each Subprocessor to fulfil its obligations in relation to the Processing of the Contracted Processors' agreements with Subprocessors (which may be redacted to remove confidential commercial information not relevant to the requirements of this Addendum) as Customer may request from time to timePersonal Data. 5.3 SentinelOne shall ensure that each Subprocessor performs its obligations under sections 2.1, 3, 4, 6.1, 7.2, 8 and 10.1, as they apply to Processing of Customer Personal Data carried out by that Subprocessor, as if it were party to this Addendum in place of SentinelOne.

Appears in 1 contract

Sources: Agreement for the Provision of Box Office & on Line Ticketing Services

Subprocessing. 5.1 3.1 Customer authorises SentinelOne ▇▇▇▇▇ to appoint (and permit each Subprocessor appointed in accordance with this section 5 to appoint) Subprocessors in accordance with this section 5 clause 3 and any restrictions in the Original Agreement. SentinelOne shall make available to Customer . 3.2 To the current list of Subprocessors extent that are processing any Subprocessor appointed by Elige processes Customer Personal DataData then, attached ▇▇▇▇▇ will remain responsible to the Customer for the Subprocessor’s obligations under this DPA. 3.3 Elige may continue to use those Subprocessors already engaged by ▇▇▇▇▇ as Annex 3at the date of this DPA as identified in the Subprocessor list which can be accessed on Elige’s Legal Repository webpage at ▇▇▇▇▇://▇▇▇.▇▇▇▇▇.▇▇/repository/Elige-Subprocessors.pdf. SentinelOne For the avoidance of doubt, Customer specifically authorises the engagement of ▇▇▇▇▇ ▇▇▇▇▇▇▇▇▇▇ as Subprocessors. 3.4 Elige shall provide give Customer prior written notice of the appointment of any new Subprocessor, including full details of the Processing to be undertaken by the SubprocessorSubprocessor by updating the Subprocessor list which is available in the Elige Legal Repository. If, within ten (10) days of receipt of that notice via the mechanism set out in this clause 3.3, Customer notifies Elige in writing of any objections (on reasonable grounds) to the proposed appointment Elige shall not appoint (or disclose any Customer Personal Data to) that proposed Subprocessor until reasonable steps have been taken to address the objections raised by Customer and Customer has been provided with a reasonable written explanation of the steps taken. If the objection cannot be resolved by the parties within thirty (30) days of receipt by ▇▇▇▇▇ of that noticethe objection, Customer notifies SentinelOne Elige shall not be in writing breach of any objections the Original Agreement to the proposed appointment, and further provides commercially reasonable justifications to such objections based on valid concerns regarding such proposed Subprocessor’s business practices relating to data protection, then (i) SentinelOne shall work with Customer in good faith to address Customer’s objections regarding the new Subprocessor; and (ii) where Customer’s concerns extent that it cannot be resolved within thirty (30) days from SentinelOne's receipt of Customer's notice, notwithstanding anything in provide the Agreement, Customer may, by providing SentinelOne Services or otherwise comply with its obligations as a written notice to with immediate effect, terminate the Agreement and SentinelOne shall refund to Customer all prepaid Fees for the Solutions attributable to the Subscription Term (as outlined in the applicable Purchase Order) following the termination of these Termsresult. 5.2 3.5 With respect to each Subprocessor, SentinelOne Elige shall: 5.2.1 before the Subprocessor first Processes Customer Personal Data, carry out adequate due diligence to ensure that the Subprocessor is capable of providing the level of protection for Customer Personal Data required by the Agreement; 5.2.2 3.5.1 ensure that the arrangement between on the one hand (a) SentinelOneElige, or (b) the relevant intermediate SubprocessorElige Affiliate; and on the other hand, the Subprocessor, is governed by a written contract including terms which offer at least the same level of protection for Customer Personal Data as those set out in this Addendum DPA, in particular in relation to requiring the Subprocessor to implement appropriate technical and organizational measures, and meet the requirements of Article 28(3) of the GDPRData Protection Laws; 5.2.3 3.5.2 if that arrangement involves a Restricted Transfer, ensure that the Standard Contractual Clauses appropriate safeguards as set out in clause 8.1.1 and clause 8.1.2 are at all relevant times incorporated into the agreement in place between on the one hand (a) SentinelOneElige, or (b) the relevant intermediate Elige Affiliate; and the Subprocessor; and on the other hand the Subprocessor, or before the Subprocessor first Processes Customer Personal Data procure that it enters into an agreement incorporating the Standard Contractual Clauses with the Customer. and 5.2.4 3.5.3 provide to Customer for review such copies of the Contracted Processors' Elige or Elige Affiliate’s agreements with Subprocessors (which may be redacted to remove confidential commercial information not relevant to the requirements of this AddendumDPA) as Customer may request from time to time. 5.3 SentinelOne 3.6 Elige shall ensure that each Subprocessor performs its the obligations under sections 2.1, 3, 4clauses 2.2, 6.1, and 7.2, 8 and 10.1, as they apply to Processing of Customer Personal Data carried out by that Subprocessor, as if it were party to this Addendum DPA in place of SentinelOneElige.

Appears in 1 contract

Sources: Data Processing Addendum

Subprocessing. 5.1 6.1. Customer authorises SentinelOne authorizes Dubsado and each Dubsado Affiliate to appoint (and permit each Subprocessor Sub- processor appointed in accordance with this section 5 6 to appoint) Subprocessors Sub-processors in accordance with this section 5 6 and any restrictions in the Principal Agreement. 6.2. SentinelOne shall make available Dubsado and each Dubsado Affiliate may continue to Customer use those Sub-processors already engaged by Dubsado or any Dubsado Affiliate as at the current date of this Addendum, subject to Dubsado and each Dubsado Affiliate in each case as soon as practicable meeting the obligations set out in section 6.4. 6.3. Dubsado maintains a list of Subprocessors that are processing sub-processors on its Privacy Policy web page, located at http:// ▇▇▇.▇▇▇▇▇▇▇.▇▇▇/▇▇▇-▇▇▇▇/ 6.3.1 Customer Personal Datashall subscribe, attached as Annex 3. SentinelOne and if Customer subscribers, Dubsado shall provide Customer prior written notice of the appointment details of any new Subprocessor, including details of the Processing changes in Sub-processors at least fourteen (14) calendar days prior to be undertaken by the Subprocessor. If, any such change. 6.3.2 If within thirty seven (307) calendar days of receipt of that notice, Customer notifies SentinelOne Dubsado in writing of any objections (on reasonable grounds) to the proposed appointment, and further provides commercially reasonable justifications to such objections based on valid concerns regarding such proposed Subprocessor’s business practices relating to data protection, then (i) SentinelOne : 6.3.2.1 Dubsado shall work with Customer in good faith to address Customer’s objections regarding make available a commercially reasonable change in the new Subprocessorprovision of the Services which avoids the use of that proposed Sub-processor with Customer Personal Data; and (ii) and 6.3.2.2 where Customer’s concerns such a change cannot be resolved made within thirty (30) 30 days from SentinelOne's Dubsado’s receipt of Customer's notice, notwithstanding anything in the Principal Agreement, Customer may, may by providing SentinelOne with a written notice to Dubsado with immediate effect, effect terminate the Principal Agreement and SentinelOne shall refund (without prejudice to any fees incurred by Customer all prepaid Fees for the Solutions attributable prior to the Subscription Term (as outlined in the applicable Purchase Order) following the termination of these Terms.termination) 5.2 6.4. With respect to each SubprocessorSub-processor, SentinelOne Dubsado or the relevant Dubsado Affiliate shall: 5.2.1 6.4.1. before the Subprocessor Sub-processor first Processes Customer Personal DataData (or, where relevant, in accordance with section 6.2), carry out adequate due diligence to ensure that the Subprocessor Sub-processor is capable of providing the level of protection for Customer Personal Data required by the Principal Agreement; 5.2.2 6.4.2. ensure that the arrangement between on the one hand (a) SentinelOneDubsado, or (b) the relevant Dubsado Affiliate, or (c) the relevant intermediate SubprocessorSub-processor; and on the other hand, hand the SubprocessorSub-processor, is governed by a written contract including terms which offer at least the same level of protection for Customer Personal Data as those set out in this Addendum and meet the requirements of Article article 28(3) of the GDPR;; and 5.2.3 if 6.4.3. If that arrangement involves a Restricted Transfer, ensure that the Standard Contractual Clauses are at all relevant times incorporated into the agreement between on the one hand hand (a) SentinelOneDubsado, or (b) the relevant intermediate Subprocessor; and on the other hand the SubprocessorDubsado Affiliate, or before the Subprocessor first Processes Customer Personal Data procure that it enters into an agreement incorporating the Standard Contractual Clauses with the Customer. and 5.2.4 provide to Customer for review such copies of the Contracted Processors' agreements with Subprocessors (which may be redacted to remove confidential commercial information not relevant to the requirements of this Addendum) as Customer may request from time to time. 5.3 SentinelOne shall ensure that each Subprocessor performs its obligations under sections 2.1, 3, 4, 6.1, 7.2, 8 and 10.1, as they apply to Processing of Customer Personal Data carried out by that Subprocessor, as if it were party to this Addendum in place of SentinelOne.or

Appears in 1 contract

Sources: Data Processing Addendum

Subprocessing. 5.1 Customer authorises SentinelOne to appoint (and permit each Subprocessor appointed in accordance with this section 5 to appoint) Subprocessors in accordance with this section 5 and any restrictions in the Agreement. SentinelOne 6.1 Vendor shall make available to Customer the current list of Subprocessors that are processing Customer Personal Data, attached as Annex 3. SentinelOne shall provide Customer give Company prior written notice of the appointment of any new Subprocessor, including full details of the Processing to be undertaken by the Subprocessor. If, within thirty (30) 15 days of receipt of that notice, Customer notifies SentinelOne Company notifies Vendor in writing of any objections (on reasonable grounds) to the proposed appointment, and further provides commercially reasonable justifications to such objections based on valid concerns regarding such : Neither Vendor nor any Vendor Affiliate shall appoint (nor disclose any Company Personal Data to) the proposed Subprocessor’s business practices relating to data protection, then (i) SentinelOne shall work Subprocessor except with Customer in good faith to address Customer’s objections regarding the new Subprocessor; and (ii) where Customer’s concerns cannot be resolved within thirty (30) days from SentinelOne's receipt prior written consent of Customer's notice, notwithstanding anything in the Agreement, Customer may, by providing SentinelOne with a written notice to with immediate effect, terminate the Agreement and SentinelOne shall refund to Customer all prepaid Fees for the Solutions attributable to the Subscription Term (as outlined in the applicable Purchase Order) following the termination of these TermsCompany. 5.2 6.2 With respect to each Subprocessor, SentinelOne Vendor or the relevant Vendor Affiliate shall: 5.2.1 6.2.1 before the Subprocessor first first Processes Customer Company Personal DataData (or, where relevant, in accordance with section 6.2), carry out adequate due diligence to ensure that the Subprocessor is capable of providing the level of protection for Customer Company Personal Data required by the Principal Agreement; 5.2.2 6.2.2 ensure that the arrangement between on the one hand (a) SentinelOneVendor, or (b) the relevant Vendor Affiliate, or (c) the relevant intermediate Subprocessor; and on the other hand, hand the Subprocessor, is governed by a written contract including terms which offer offer at least the same level of protection for Customer Company Personal Data as those set out in this Addendum and meet the requirements of Article article 28(3) of the GDPR; 5.2.3 6.2.3 if that arrangement involves a Restricted Transfer, ensure that the Standard Contractual Clauses are at all relevant times incorporated into the agreement between on the one hand hand (a) SentinelOneVendor, or (b) the relevant Vendor Affiliate, or (c) the relevant intermediate Subprocessor; and on the other hand the Subprocessor, or before the Subprocessor first first Processes Customer Company Personal Data procure that it enters into an agreement incorporating the Standard Contractual Clauses with the Customer. relevant Company Group Member(s) (and Company shall procure that each Company Affiliate party to any such Standard Contractual Clauses co-operates with their population and execution); and 5.2.4 6.2.4 provide to Customer Company for review such copies of the Contracted Processors' agreements with Subprocessors (which may be redacted to remove confidential confidential commercial information not relevant to the requirements of this Addendum) as Customer Company may request from time to time. 5.3 SentinelOne 6.3 Vendor and each Vendor Affiliate shall ensure that each Subprocessor performs its the obligations under sections 2.1, 33.1, 4, 6.15, 7.27.1, 8 8.2, 9 and 10.111.1, as they apply to Processing of Customer Company Personal Data carried out by that Subprocessor, as if it were party to this Addendum in place of SentinelOneVendor.

Appears in 1 contract

Sources: Data Protection Addendum

Subprocessing. 5.1 Customer 6.1 Each Company Group Member authorises SentinelOne Vendor and each Vendor Affiliate to appoint (and permit each Subprocessor appointed in accordance with this section 5 6 to appoint) Subprocessors in accordance with this section 5 6 and any restrictions in the Principal Agreement. SentinelOne . 6.2 Vendor and each Vendor Affiliate may continue to use those Subprocessors already engaged by Vendor or any Vendor Affiliate as at the date of this Addendum, subject to Vendor and each Vendor Affiliate in each case as soon as practicable meeting the obligations set out in section 6.4. 6.3 Vendor shall make available to Customer the current list of Subprocessors that are processing Customer Personal Data, attached as Annex 3. SentinelOne shall provide Customer give Company prior written notice of the appointment of any new Subprocessor, including full details of the Processing to be undertaken by the Subprocessor. If, within thirty (30) 5 business days of receipt of that notice, Customer Company notifies SentinelOne Vendor in writing of any objections (on reasonable grounds) to the proposed appointment, and further provides commercially reasonable justifications to such objections based on valid concerns regarding such : Neither Vendor nor any Vendor Affiliate shall appoint (nor disclose any Company Personal Data to) the proposed Subprocessor’s business practices relating to data protection, then (i) SentinelOne shall work Subprocessor except with Customer in good faith to address Customer’s objections regarding the new Subprocessor; and (ii) where Customer’s concerns cannot be resolved within thirty (30) days from SentinelOne's receipt prior written consent of Customer's notice, notwithstanding anything in the Agreement, Customer may, by providing SentinelOne with a written notice to with immediate effect, terminate the Agreement and SentinelOne shall refund to Customer all prepaid Fees for the Solutions attributable to the Subscription Term (as outlined in the applicable Purchase Order) following the termination of these TermsCompany. 5.2 6.4 With respect to each Subprocessor, SentinelOne Vendor or the relevant Vendor Affiliate shall: 5.2.1 6.4.1 before the Subprocessor first Processes Customer Company Personal DataData (or, where relevant, in accordance with section 6.2), carry out adequate due diligence to ensure that the Subprocessor is capable of providing the level of protection for Customer Company Personal Data required by the Principal Agreement; 5.2.2 6.4.2 ensure that the arrangement between on the one hand (a) SentinelOneVendor, or (b) the relevant Vendor Affiliate, or (c) the relevant intermediate Subprocessor; and on the other hand, hand the Subprocessor, is governed by a written contract including terms which offer at least the same level of protection for Customer Company Personal Data as those set out in this Addendum and meet the requirements of Article article 28(3) of the GDPR; 5.2.3 6.4.3 if that arrangement involves a Restricted Transfer, ensure that the Standard Contractual Clauses are at all relevant times incorporated into the agreement between on the one hand hand (a) SentinelOneVendor, or (b) the relevant Vendor Affiliate, or (c) the relevant intermediate Subprocessor; and on the other hand the Subprocessor, or before the Subprocessor first Processes Customer Company Personal Data procure that it enters into an agreement incorporating the Standard Contractual Clauses with the Customer. relevant Company Group Member(s) (and Company shall procure that each Company Affiliate party to any such Standard Contractual Clauses co-operates with their population and execution); and 5.2.4 6.4.4 provide to Customer Company for review such copies of the Contracted Processors' agreements with Subprocessors (which may be redacted to remove confidential commercial information not relevant to the requirements of this Addendum) as Customer Company may request from time to time. 5.3 SentinelOne 6.5 Vendor and each Vendor Affiliate shall ensure that each Subprocessor performs its the obligations under sections 2.1, 33.1, 4, 6.15, 7.27.1, 8 8.2, 9 and 10.111.1, as they apply to Processing of Customer Company Personal Data carried out by that Subprocessor, as if it were party to this Addendum in place of SentinelOneVendor.

Appears in 1 contract

Sources: Data Processing Addendum

Subprocessing. 5.1 Customer authorises SentinelOne CUSTOMER authorizes GERBER and each GERBER Affiliate to appoint (and permit each Subprocessor appointed in accordance with this section 5 to appoint) Subprocessors in accordance with this section 5 and 5, subject to any restrictions in the Principal Agreement. SentinelOne , to conduct Processing described in clause 2.3. 5.2 GERBER and each GERBER Affiliate may use for the Processing of CUSTOMER Personal Data the Subprocessors which have been already engaged by GERBER or any GERBER Affiliate as of the date of this Addendum. 5.3 GERBER shall make available to Customer the current list of Subprocessors that are processing Customer Personal Data, attached as Annex 3. SentinelOne shall provide Customer give CUSTOMER prior written notice of the appointment of any new Subprocessor, including full details of the Processing to be undertaken by the Subprocessor. If, within thirty (30) 10 days of receipt of that notice, Customer CUSTOMER notifies SentinelOne GERBER in writing of any objections (on reasonable grounds) to the proposed appointment, and further provides commercially reasonable justifications neither GERBER nor any GERBER Affiliate shall appoint (nor disclose nor transfer any CUSTOMER Personal Data to) the proposed Subprocessor except with the prior written consent of CUSTOMER. If CUSTOMER objects to such objections based on valid concerns regarding such the appointment of a proposed Subprocessor’s business practices relating Subprocessor then GERBER shall be entitled to data protection, then (i) SentinelOne shall work with Customer in good faith to address Customer’s objections regarding either propose another Subprocessor or terminate the new Subprocessor; and (ii) where Customer’s concerns cannot be resolved within thirty (30) days from SentinelOne's receipt of Customer's notice, notwithstanding anything in the Agreement, Customer may, respective Service by providing SentinelOne with a written notice to with immediate effect, terminate the Agreement and SentinelOne shall refund to Customer all prepaid Fees for the Solutions attributable to the Subscription Term (as outlined in the applicable Purchase Order) following the termination of these TermsCUSTOMER. 5.2 5.4 With respect to each Subprocessor, SentinelOne GERBER or the relevant GERBER Affiliate shall: 5.2.1 5.4.1 before the Subprocessor first Processes Customer CUSTOMER Personal Data, Data carry out adequate due diligence to ensure that the Subprocessor is capable of providing the level of protection for Customer CUSTOMER Personal Data required by the AgreementPrincipal Agreement and this Addendum; 5.2.2 5.4.2 ensure that the arrangement between on the one hand (a) SentinelOneGERBER, or (b) the relevant GERBER Affiliate, or (c) the relevant intermediate Subprocessor; and on the other hand, hand the Subprocessor, is governed by a written contract including terms which that offer at least the same level of protection for Customer CUSTOMER Personal Data as those set out in this Addendum and meet the requirements of Article article 28(3) of the GDPR;; and 5.2.3 5.4.3 if that arrangement involves a Restricted Transfer, (a) ensure that the Standard Contractual Clauses are at all relevant times properly incorporated into the agreement between on GERBER or the one hand (a) SentinelOnerelevant GERBER Affiliate and the Subprocessor, or (b) the relevant intermediate Subprocessor; and on the other hand the Subprocessor, or before the Subprocessor first Processes Customer CUSTOMER Personal Data procure that it enters Data, require the Subprocessor to enter into an agreement incorporating with CUSTOMER that incorporates the Standard Contractual Clauses with the Customer. and 5.2.4 provide to Customer for review such copies of the Contracted Processors' agreements with Subprocessors (which may be redacted to remove confidential commercial information not relevant to the requirements of this Addendum) as Customer may request from time to timeClauses. 5.3 SentinelOne shall ensure that each Subprocessor performs its obligations under sections 2.1, 3, 4, 6.1, 7.2, 8 and 10.1, as they apply to Processing of Customer Personal Data carried out by that Subprocessor, as if it were party to this Addendum in place of SentinelOne.

Appears in 1 contract

Sources: Data Processing Addendum

Subprocessing. 5.1 10.1 Customer authorises SentinelOne acknowledges, agrees and authorizes, that Hubilo may engage Sub Processors for certain Processing activities as required from time to appoint (and permit each Subprocessor appointed time on Customer's behalf in accordance with this section 5 8 and subject to appoint) Subprocessors in accordance with this section 5 and any restrictions in the Agreement. SentinelOne MSA. 10.2 Hubilo and each Hubilo Affiliate may continue to use those Sub-processors already engaged by Hubilo and each Hubilo Affiliate as at the date of this Addendum, subject to Hubilo and each Hubilo Affiliate in each case as soon as practicable meeting the obligations set out in section 7. 10.3 Hubilo and/or the relevant Hubilo Affiliate shall make available to Customer give the current list of Subprocessors that are processing Customer Personal Data, attached as Annex 3. SentinelOne shall provide Customer prior written notice of the appointment of any new SubprocessorSub-processors, including full details of the Processing to be undertaken by the SubprocessorSub-processors within 30 (thirty) days of such appointment. If, within thirty 10 (30ten) days of receipt of that notice, Customer notifies SentinelOne Hubilo and/or the relevant Hubilo Affiliate in writing of any objections (on reasonable grounds) to the proposed appointment, and further provides commercially reasonable justifications to such objections based on valid concerns regarding such proposed Subprocessor’s business practices relating to data protection, then (i) SentinelOne Hubilo and/or the relevant Hubilo Affiliate shall work with Customer in good faith to address Customer’s objections regarding the new Subprocessor; and (ii) where Customer’s concerns cannot be resolved within thirty (30) days from SentinelOne's receipt of Customer's notice, notwithstanding anything make available a commercially reasonable change in the Agreement, Customer may, by providing SentinelOne with a written notice to with immediate effect, terminate provision of the Agreement and SentinelOne shall refund to Customer all prepaid Fees for Services which avoids the Solutions attributable to the Subscription Term (as outlined in the applicable Purchase Order) following the termination use of these Termsthat proposed Sub-processors. 5.2 10.4 With respect to each SubprocessorSub Processor, SentinelOne Hubilo and/or the relevant Hubilo Affiliate shall: 5.2.1 before the Subprocessor first Processes Customer Personal Data, carry out adequate due diligence to ensure that the Subprocessor is capable of providing the level of protection for Customer Personal Data required by the Agreement; 5.2.2 i) ensure that the arrangement between on the one hand (a) SentinelOneHubilo, or (b) the relevant intermediate Subprocessor; Hubilo Affiliate, and on the other hand, hand the Subprocessor, is governed by a written contract including terms which offer at least the same level of protection for Customer Personal Data as those set out in this Addendum and meet the requirements of Article article 28(3) of the GDPR; 5.2.3 ii) if that arrangement involves a Restricted Transfer, Hubilo shall ensure that the Standard Contractual Clauses are at all relevant times incorporated into the agreement between on the one hand (a) SentinelOneHubilo, or (b) the relevant intermediate Subprocessor; Hubilo Affiliate, and on the other hand the Subprocessor, or before the Subprocessor first Processes Customer Personal Data procure that it enters into an agreement incorporating the Standard Contractual Clauses with the Customer. ; and 5.2.4 iii) provide to Customer for review such copies of Hubilo's or the Contracted Processors' agreements relevant Hubilo Affiliate’s agreements, as applicable, with Subprocessors Sub-processors (which may be redacted to remove confidential commercial information not relevant to the requirements of this Addendum) as Customer may request from time to time. 5.3 SentinelOne shall ensure that each Subprocessor performs its obligations under sections 2.1, 3, 4, 6.1, 7.2, 8 and 10.1, as they apply to Processing of Customer Personal Data carried out by that Subprocessor, as if it were party to this Addendum in place of SentinelOne.

Appears in 1 contract

Sources: Data Processing Agreement

Subprocessing. 5.1 Customer 9.5.1 Client authorises SentinelOne Supplier to appoint (and permit each Subprocessor appointed in accordance with this section 5 to appoint) Subprocessors in accordance with this section 5 and any restrictions in the Agreement. SentinelOne . 9.5.2 Client specifically authorises no subprocessors are currently engaged to act as a sub- processor on behalf of Client ("Subprocessor List") to Process Client Personal Data as required to provide the Services, subject to Supplier in each case, as soon as practicable, meeting the obligations set out in Clause 9.5.4 (in each case, an "Authorised Sub- Processor"). 9.5.3 Supplier shall make available to Customer ensure the current list Client receives a notification as soon as reasonable practicable of Subprocessors that are processing Customer Personal Data, attached as Annex 3. SentinelOne shall provide Customer prior written notice any intended changes concerning the addition or replacement of any of the appointment of Authorised Sub- Processors, that will Process any new Subprocessor, including details of the Processing to be undertaken by the SubprocessorClient Personal Data ("New Sub-Processor"). If, within thirty (30) 14 calendar days of receipt of that notice, Customer Client notifies SentinelOne Supplier in writing of any objections (on reasonable grounds) to the proposed appointmentappointment of a New Sub-Processor, and further provides the parties will endeavour to agree (acting reasonably) the commercially reasonable justifications steps to such objections based on valid concerns regarding such proposed Subprocessor’s business practices relating be taken to data protectionensure that the New Subprocessor in question is compliant with Article 28(4) of the Data Protection Laws. Where the Client considers, then (i) SentinelOne shall work acting reasonably, that the risks involved with Customer in good faith to address Customer’s objections regarding the new Subprocessor; and (ii) where Customer’s concerns cannot be resolved within thirty (30) days from SentinelOne's receipt of Customer's notice, notwithstanding anything subprocessing are still unacceptable in the Agreementcontext of Article 28(4), Customer may, by providing SentinelOne with a written notice to with immediate effect, terminate within 30 calendar days following the Agreement and SentinelOne shall refund to Customer all prepaid Fees for the Solutions attributable proposal in relation to the Subscription Term (as outlined in appropriate steps, the applicable Purchase Order) following parties shall promptly seek to resolve the termination of these Termsissues. 5.2 9.5.4 With respect to each Authorised Subprocessor, SentinelOne Supplier shall: 5.2.1 before the Subprocessor first Processes Customer Personal Data, carry out adequate due diligence to ensure that the Subprocessor is capable of providing the level of protection for Customer Personal Data required by the Agreement; 5.2.2 : (i) ensure that the arrangement between on Supplier and the one hand Authorised Subprocessor is governed by terms and conditions or a service agreement which offers no less protection for Client Personal Data as those terms set out in the Agreement and (ii) if that arrangement involves the transfer of Personal Data to a country outside of the EEA that has not been determined to ensure an adequate level of protection for Personal Data, at Supplier's discretion: Supplier will either (a) SentinelOneensure that an appropriate data transfer safeguard is in place in compliance with Chapter V of the Data Protection Laws, or (b) where required to ensure compliance with Data Protection Laws, use commercially reasonable endeavours to procure that the Subprocessor enters into standard contractual clauses approved by the ICO or European Commission (as appropriate) directly with the relevant intermediate Subprocessor; and on the other hand, the Subprocessor, is governed by a written contract including terms which offer at least the same level of protection for Customer Personal Data as those set out in this Addendum and meet the requirements of Article 28(3) of the GDPR; 5.2.3 if that arrangement involves a Restricted Transfer, ensure that the Standard Contractual Clauses are at all relevant times incorporated into the agreement between on the one hand (a) SentinelOne, or (b) the relevant intermediate Subprocessor; and on the other hand the Subprocessor, or before the Subprocessor first Processes Customer Personal Data procure that it enters into an agreement incorporating the Standard Contractual Clauses with the Customer. and 5.2.4 provide to Customer for review such copies of the Contracted Processors' agreements with Subprocessors (which may be redacted to remove confidential commercial information not relevant to the requirements of this Addendum) as Customer may request from time to timeClient. 5.3 SentinelOne shall ensure that each Subprocessor performs its obligations under sections 2.1, 3, 4, 6.1, 7.2, 8 and 10.1, as they apply to Processing of Customer Personal Data carried out by that Subprocessor, as if it were party to this Addendum in place of SentinelOne.

Appears in 1 contract

Sources: Terms and Conditions

Subprocessing. Where there is no subprocessing at the date of this addendum, these clauses cover GDPR requirements in the event that subprocessors are required at a future date. 5.1 Customer The Client authorises SentinelOne Oleeo to appoint (and permit each Subprocessor appointed in accordance with this section paragraph 5 to appoint) Subprocessors in accordance with this section paragraph 5 and any restrictions in the Agreementagreement. SentinelOne Oleeo Standdard Terms v27x GC Page 27 of 32 5.2 Where applicable, Oleeo may continue to use those Subprocessors already engaged by Oleeo as at the date of this Schedule, subject to Oleeo as soon as practicable meeting the obligations set out in paragraph 5.4. 5.3 Oleeo shall make available to Customer give the current list of Subprocessors that are processing Customer Personal Data, attached as Annex 3. SentinelOne shall provide Customer Client prior written notice of the appointment of any new Subprocessor, including full details of the Processing to be undertaken by the Subprocessor. If, within thirty (30) fourteen days of receipt of that notice, Customer the Client notifies SentinelOne Oleeo in writing of any objections (on reasonable grounds) to the proposed appointment, and further provides commercially Oleeo shall not appoint (or disclose any Client Personal Data to) that proposed Subprocessor until reasonable justifications to such objections based on valid concerns regarding such proposed Subprocessor’s business practices relating to data protection, then (i) SentinelOne shall work with Customer in good faith steps have been taken to address Customer’s the objections regarding raised by the new Subprocessor; Client and (ii) where Customer’s concerns cannot be resolved within thirty (30) days from SentinelOne's receipt of Customer's notice, notwithstanding anything in the Agreement, Customer may, by providing SentinelOne Client has been provided with a reasonable written notice to with immediate effect, terminate explanation of the Agreement and SentinelOne shall refund to Customer all prepaid Fees for the Solutions attributable to the Subscription Term (as outlined in the applicable Purchase Order) following the termination of these Termssteps taken. 5.2 5.4 With respect to each Subprocessor, SentinelOne Oleeo shall: 5.2.1 5.4.1 before the Subprocessor first Processes Customer Client Personal DataData (or, where relevant, in accordance with paragraph 5.2), carry out adequate due diligence to ensure that the Subprocessor is capable of providing the level of protection for Customer Client Personal Data required by the Agreementagreement; 5.2.2 5.4.2 ensure that the arrangement between on the one hand (a) SentinelOneOleeo, or (b) the relevant intermediate Subprocessor; and on the other hand, hand the Subprocessor, is governed by a written contract including terms which impose substantively the same obligations on the Subprocessor as this Schedule imposes on Oleeo, which offer at least the same level of protection for Customer Client Personal Data as those set out in this Addendum Schedule and meet the requirements of Article article 28(3) of the GDPR; 5.2.3 5.4.3 if that arrangement involves a Restricted Transfer, ensure that the Standard Contractual Clauses are at all relevant times incorporated into the agreement between on the one hand hand (a) SentinelOneOleeo, or (b) the relevant intermediate Subprocessor; and on the other hand hand, the SubprocessorSubprocessor or, or before the Subprocessor first Processes Customer Client Personal Data Data, procure that it enters into an agreement incorporating the Standard Contractual Clauses with the Customer. Client; and 5.2.4 5.4.4 provide to Customer the Client for review such copies of the Contracted Processors' agreements with Subprocessors (which may be redacted to remove confidential commercial information not relevant to the requirements of this AddendumSchedule) as Customer the Client may request from time to time. 5.3 SentinelOne 5.5 Oleeo shall ensure that each Subprocessor performs its the obligations under sections paragraphs 2.1, 3, 4, 6.1, 7.2, 8 9 and 10.1, as they apply to Processing of Customer Client Personal Data carried out by that Subprocessor, as if it were party to this Addendum Schedule in place of SentinelOneOleeo.

Appears in 1 contract

Sources: Recruitment Application Service Agreement

Subprocessing. 5.1 Customer authorises SentinelOne Each Company Group Member authorizes Vendor to appoint (and permit each Subprocessor appointed in accordance with section 6 of this section 5 DPA to appoint) Subprocessors in accordance with this section 5 and any restrictions in the Agreement. SentinelOne . 5.2 Vendor may continue to use those Subprocessors already engaged by Vendor as at the date of this DPA, subject to Vendor in each case as soon as practicable meeting the obligations set out in section 5.4. 5.3 Vendor shall make available to Customer the current list of Subprocessors that are processing Customer Personal Data, attached as Annex 3. SentinelOne shall provide Customer give Company prior written notice of the appointment of any new Subprocessor, including full details of the Processing to be undertaken by the Subprocessor. If, within thirty (30) 14 Calendar days of receipt of that notice, Customer Company notifies SentinelOne Vendor in writing of any objections (on reasonable grounds) to the proposed appointment, and further provides commercially : Vendor shall not appoint (or disclose any Company Personal Data to) the proposed Subprocessor until reasonable justifications to such objections based on valid concerns regarding such proposed Subprocessor’s business practices relating to data protection, then (i) SentinelOne shall work with Customer in good faith steps have been taken to address Customer’s the objections regarding the new Subprocessor; raised by any Company Group Member and (ii) where Customer’s concerns cannot be resolved within thirty (30) days from SentinelOne's receipt of Customer's notice, notwithstanding anything in the Agreement, Customer may, by providing SentinelOne Company has been provided with a reasonable written notice to with immediate effect, terminate explanation of the Agreement and SentinelOne shall refund to Customer all prepaid Fees for the Solutions attributable to the Subscription Term (as outlined in the applicable Purchase Order) following the termination of these Termssteps taken. 5.2 5.4 With respect to each Subprocessor, SentinelOne Vendor shall: 5.2.1 5.4.1 before the Subprocessor first Processes Customer Company Personal DataData (or, where relevant, in accordance with section 5.2), carry out adequate due diligence to ensure that the Subprocessor is capable of providing the level of protection for Customer Company Personal Data required by the Agreement; 5.2.2 5.4.2 ensure that the arrangement between on the one hand (a) SentinelOne, Vendor or (b) the relevant intermediate Subprocessor; and on the other hand, hand the Subprocessor, is governed by a written contract including terms which offer at least the same level of protection for Customer Company Personal Data as those set out in this Addendum DPA and meet the requirements of Article article 28(3) of the GDPR; 5.2.3 if that arrangement involves a Restricted Transfer, ensure that the Standard Contractual Clauses are at all relevant times incorporated into the agreement between on the one hand (a) SentinelOne, or (b) the relevant intermediate Subprocessor; and on the other hand the Subprocessor, or before the Subprocessor first Processes Customer Personal Data procure that it enters into an agreement incorporating the Standard Contractual Clauses with the Customer. and 5.2.4 5.4.3 upon request provide to Customer Company for review such copies of the Contracted Processors' Processors agreements with Subprocessors (which may be redacted to remove confidential commercial information not relevant to the requirements of this AddendumDPA) as Customer Company may request from time to time. 5.3 SentinelOne 5.5 Vendor shall ensure that each Subprocessor performs its the obligations under sections 2.1, 3, 4, 6.1, 7.2, 8 and 10.1, this DPA as they apply to Processing of Customer Company Personal Data carried out by that Subprocessor, as if it were party to this Addendum DPA in place of SentinelOneVendor.

Appears in 1 contract

Sources: Data Protection Addendum

Subprocessing. 5.1 Customer Company authorises SentinelOne ChallengeRunner to appoint (and permit each Subprocessor appointed in accordance with this section Section 5 to appoint) Subprocessors in accordance with this section Section 5 and any restrictions in the Principal Agreement. SentinelOne . 5.2 ChallengeRunner may continue to use those Subprocessors already engaged by ChallengeRunner as at the date of this Addendum, subject to ChallengeRunner as soon as practicable meeting the obligations set out in Section 5.4. 5.3 ChallengeRunner shall make available to Customer the current list of Subprocessors that are processing Customer Personal Data, attached as Annex 3. SentinelOne shall provide Customer give Company prior written notice of the appointment of any new Subprocessor, including full details of the Processing to be undertaken by the Subprocessor. If, within thirty (30) days of receipt of that notice, Customer Company notifies SentinelOne ChallengeRunner in writing of any objections (on reasonable grounds) to the proposed appointment, and further provides commercially reasonable justifications to such objections based on valid concerns regarding such proposed Subprocessor’s business practices relating to data protection, then (i) SentinelOne : 5.3.1 ChallengeRunner shall work with Customer Company in good faith to address Customer’s objections regarding make available a commercially reasonable change in the new provision of the Services which avoids the use of that proposed Subprocessor; and (ii) and 5.3.2 where Customer’s concerns such a change cannot be resolved made within thirty (30) days from SentinelOneChallengeRunner's receipt of CustomerCompany's notice, notwithstanding anything in the Principal Agreement, Customer may, Company may by providing SentinelOne with a written notice to ChallengeRunner with immediate effect, effect terminate the Principal Agreement and SentinelOne shall refund to Customer all prepaid Fees for the Solutions attributable to the Subscription Term (as outlined in extent that it relates to the applicable Purchase Order) following Services which require the termination use of these Termsthe proposed Subprocessor. 5.2 5.4 With respect to each Subprocessor, SentinelOne ChallengeRunner or shall: 5.2.1 5.4.1 before the Subprocessor first Processes Customer Company Personal DataData (or, where relevant, in accordance with Section 5.2), carry out adequate due diligence to ensure that the Subprocessor is capable of providing the level of protection for Customer Company Personal Data required by the Principal Agreement; 5.2.2 5.4.2 ensure that the arrangement between on the one hand (a) SentinelOneChallengeRunner, or (bc) the relevant intermediate Subprocessor; and on the other hand, hand the Subprocessor, is governed by a written contract including terms which offer at least the same level of protection for Customer Company Personal Data as those set out in this Addendum and meet the requirements of Article article 28(3) of the GDPR; 5.2.3 5.4.3 if that arrangement involves a Restricted Transfer, ensure that the Standard Contractual Clauses are at all relevant times incorporated into the agreement between on the one hand hand (a) SentinelOneChallengeRunner, or (bc) the relevant intermediate Subprocessor; and on the other hand the Subprocessor, or before the Subprocessor first Processes Customer Company Personal Data procure that it enters into an agreement incorporating the Standard Contractual Clauses with the Customer. Company; and 5.2.4 5.4.4 provide to Customer Company for review such copies of the Contracted Processors' agreements with Subprocessors (which may be redacted to remove confidential commercial information not relevant to the requirements of this Addendum) as Customer Company may request from time to time. 5.3 SentinelOne 5.5 ChallengeRunner shall ensure that each Subprocessor performs its the obligations under sections 2.1Sections 2.2, 3, 4, 6.1, 7.2, 8 and 8, 10.1, as they apply to Processing of Customer Company Personal Data carried out by that Subprocessor, as if it were party to this Addendum in place of SentinelOneChallengeRunner.

Appears in 1 contract

Sources: Data Protection Addendum

Subprocessing. 5.1 Customer 6.1 Each Company Group Member authorises SentinelOne Vendor and each Vendor Affiliate to appoint (and permit each Subprocessor appointed in accordance with this section 5 6 to appoint) Subprocessors in accordance with this section 5 6 and any restrictions in the Principal Agreement. SentinelOne shall make . 6.2 Vendor and each Vendor Affiliate may continue to use those Subprocessors already engaged by Vendor or any Vendor Affiliate as at the date of this Addendum, subject to Vendor and each Vendor Affiliate in each case as soon as practicable meeting the obligations set out in section 6.4. 6.3 An up to notice of all Subprocessors is available to Customer the current list of Subprocessors that are processing Customer Personal Data, attached as Annex 3. SentinelOne shall provide Customer prior written notice of the appointment of any new Subprocessor, including details of the Processing to Company upon request and will be undertaken by the Subprocessor. provided within 5 business days. 6.4 If, within thirty (30) 5 business days of receipt of that notice, Customer Company notifies SentinelOne Vendor in writing of any objections (on reasonable grounds) to the proposed appointment, and further provides commercially reasonable justifications to such objections based on valid concerns regarding such proposed Subprocessor’s business practices relating to data protection, then (i) SentinelOne : 6.4.1 Vendor shall work with Customer Company in good faith to address Customer’s objections regarding the new Subprocessor; and (ii) where Customer’s concerns cannot be resolved within thirty (30) days from SentinelOne's receipt of Customer's notice, notwithstanding anything make available a commercially reasonable change in the Agreement, Customer may, by providing SentinelOne with a written notice to with immediate effect, terminate provision of the Agreement and SentinelOne shall refund to Customer all prepaid Fees for Services which avoids the Solutions attributable to the Subscription Term (as outlined in the applicable Purchase Order) following the termination use of these Termsthat proposed Subprocessor. 5.2 6.5 With respect to each Subprocessor, SentinelOne Vendor or the relevant Vendor Affiliate shall: 5.2.1 6.5.1 before the Subprocessor first Processes Customer Company Personal DataData (or, where relevant, in accordance with section 6.2), carry out adequate due diligence to ensure that the Subprocessor is capable of providing the level of protection for Customer Company Personal Data required by the Principal Agreement; 5.2.2 6.5.2 ensure that the arrangement between on the one hand (a) SentinelOneVendor, or (b) the relevant Vendor Affiliate, or (c) the relevant intermediate Subprocessor; and on the other hand, hand the Subprocessor, is governed by a written contract including terms which offer at least the same level of protection for Customer Company Personal Data as those set out in this Addendum and meet the requirements of Article article 28(3) of the GDPR; 5.2.3 if that arrangement involves a Restricted Transfer, ensure that the Standard Contractual Clauses are at all relevant times incorporated into the agreement between on the one hand (a) SentinelOne, or (b) the relevant intermediate Subprocessor; and on the other hand the Subprocessor, or before the Subprocessor first Processes Customer Personal Data procure that it enters into an agreement incorporating the Standard Contractual Clauses with the Customer. and 5.2.4 6.5.3 provide to Customer Company for review such copies of the Contracted Processors' agreements with Subprocessors (which may be redacted to remove confidential commercial information not relevant to the requirements of this Addendum) as Customer Company may request from time to time. 5.3 SentinelOne 6.6 Vendor and each Vendor Affiliate shall ensure that each Subprocessor performs its the obligations under sections 2.1, 33.1, 4, 6.15, 7.27.1, 8 8.2, 9 and 10.111.1, as they apply to Processing of Customer Company Personal Data carried out by that Subprocessor, as if it were party to this Addendum in place of SentinelOneVendor.

Appears in 1 contract

Sources: Data Protection Addendum

Subprocessing. 5.1 Customer authorises SentinelOne Each Company Group Member authorizes Vendor to appoint (and permit each Subprocessor appointed in accordance with this section 5 6 to appoint) Subprocessors in accordance with this section 5 and any restrictions in the Principal Agreement. SentinelOne . 5.2 Vendor may continue to use those Subprocessors already engaged by Vendor as at the date of this Addendum, subject to Vendor in each case as soon as practicable meeting the obligations set out in section 5.4. 5.3 Vendor shall make available to Customer the current list of Subprocessors that are processing Customer Personal Data, attached as Annex 3. SentinelOne shall provide Customer give Company prior written notice of the appointment of any new Subprocessor, including full details of the Processing to be undertaken by the Subprocessor. If, within thirty (30) 14 Calendar days of receipt of that notice, Customer Company notifies SentinelOne Vendor in writing of any objections (on reasonable grounds) to the proposed appointment, and further provides commercially : Vendor shall appoint (or disclose any Company Personal Data to) that proposed Subprocessor until reasonable justifications to such objections based on valid concerns regarding such proposed Subprocessor’s business practices relating to data protection, then (i) SentinelOne shall work with Customer in good faith steps have been taken to address Customer’s the objections regarding the new Subprocessor; raised by any Company Group Member and (ii) where Customer’s concerns cannot be resolved within thirty (30) days from SentinelOne's receipt of Customer's notice, notwithstanding anything in the Agreement, Customer may, by providing SentinelOne Company has been provided with a reasonable written notice to with immediate effect, terminate explanation of the Agreement and SentinelOne shall refund to Customer all prepaid Fees for the Solutions attributable to the Subscription Term (as outlined in the applicable Purchase Order) following the termination of these Termssteps taken. 5.2 5.4 With respect to each Subprocessor, SentinelOne Vendor shall: 5.2.1 5.4.1 before the Subprocessor first Processes Customer Company Personal DataData (or, where relevant, in accordance with section 5.2), carry out adequate due diligence to ensure that the Subprocessor is capable of providing the level of protection for Customer Company Personal Data required by the Principal Agreement; 5.2.2 5.4.2 ensure that the arrangement between on the one hand (a) SentinelOne, Vendor or (b) the relevant intermediate Subprocessor; and on the other hand, hand the Subprocessor, is governed by a written contract including terms which offer at least the same level of protection for Customer Company Personal Data as those set out in this Addendum and meet the requirements of Article article 28(3) of the GDPR; 5.2.3 if that arrangement involves a Restricted Transfer, ensure that the Standard Contractual Clauses are at all relevant times incorporated into the agreement between on the one hand (a) SentinelOne, or (b) the relevant intermediate Subprocessor; and on the other hand the Subprocessor, or before the Subprocessor first Processes Customer Personal Data procure that it enters into an agreement incorporating the Standard Contractual Clauses with the Customer. and 5.2.4 5.4.3 upon request provide to Customer Company for review such copies of the Contracted Processors' Processors agreements with Subprocessors (which may be redacted to remove confidential commercial information not relevant to the requirements of this Addendum) as Customer Company may request from time to time. 5.3 SentinelOne 5.5 Vendor shall ensure that each Subprocessor performs its the obligations under sections 2.1, 3, 4, 6.1, 7.2, 8 and 10.1, as they apply to Processing of Customer Company Personal Data carried out by that Subprocessor, as if it were party to this Addendum in place of SentinelOneVendor.

Appears in 1 contract

Sources: Data Protection Addendum

Subprocessing. 5.1 Customer authorises SentinelOne Supplier will not give access to appoint or transfer any Conversant Personal Data to any third party (including any of Supplier’s Affiliates, group companies or Subprocessors) without the prior written consent of Conversant. Notwithstanding the foregoing, where Supplier is a Processor, Conversant does consent to Supplier engaging a Subprocessor to Process Conversant Personal Data provided that: (a) Supplier conducts appropriate due diligence to ensure it retains Subprocessors which present sufficient guarantees in terms of confidentiality, security and permit each Subprocessor appointed data protection in accordance with this section 5 to appointData Protection Legislation; (b) Subprocessors in accordance with this section 5 and any restrictions in the Agreement. SentinelOne shall make available to Customer the current list of Subprocessors that are processing Customer Personal Data, attached as Annex 3. SentinelOne shall provide Customer Supplier provides at least 30 days’ prior written notice to Conversant of the appointment engagement of any new Subprocessor, Subprocessor (including details of the Processing and location) and Supplier shall update the list of all Subprocessors engaged to be undertaken by Process Conversant Personal Data under the DPA and send such updated version to Conversant prior to the engagement of the Subprocessor. If, within thirty ; (30c) days Supplier must ensure the Subprocessor is a "service provider" as such term is defined under US Data Protection Law or any similar or analogous designation under Data Protection Legislation; (d) Supplier must ensure the reliability and competence of receipt of that notice, Customer notifies SentinelOne in writing of any objections to the proposed appointmentsuch Subprocessor, and further provides commercially reasonable justifications of its Authorized Personnel who may have access to Conversant Personal Data; (e) Supplier imposes in its contract with such objections based on valid concerns regarding such proposed Subprocessor’s business practices relating to data protection, then (i) SentinelOne shall work with Customer in good faith to address Customer’s objections regarding the new Subprocessor; and (ii) where Customer’s concerns cannot be resolved within thirty (30) days from SentinelOne's receipt Subprocessor provisions which are at least as protective of Customer's notice, notwithstanding anything Conversant as those in the Agreement, Customer may, by providing SentinelOne with a written notice to with immediate effect, terminate DPA and the Services Agreement and SentinelOne shall refund as required by Data Protection Legislation; and (f) Supplier is fully liable to Customer all prepaid Fees Conversant for any breach of the Solutions attributable to DPA and the Subscription Term (as outlined in the applicable Purchase Order) following the termination Services Agreement caused by an act, error or omission of these Termsa Subprocessor including Authorized Personnel. 5.2 With respect If Conversant objects to each Subprocessorthe engagement of any Subprocessor on data protection grounds, SentinelOne shall: 5.2.1 before then either Supplier will not engage the Subprocessor first Processes Customer Personal Data, carry out adequate due diligence to ensure that the Subprocessor is capable of providing the level of protection for Customer Process Conversant Personal Data required by or Conversant may elect to immediately suspend or terminate the Agreement; 5.2.2 ensure that Services Agreement or the arrangement between on the one hand (a) SentinelOne, or (b) the relevant intermediate Subprocessor; and on the other hand, the Subprocessor, is governed by a written contract including terms which offer at least the same level Processing of protection for Customer Conversant Personal Data as those set out under the Services Agreement, in this Addendum and meet the requirements of Article 28(3) of the GDPR; 5.2.3 if that arrangement involves a Restricted Transfer, ensure that the Standard Contractual Clauses are at all relevant times incorporated into the agreement between on the one hand (a) SentinelOne, or (b) the relevant intermediate Subprocessor; and on the other hand the Subprocessor, or before the Subprocessor first Processes Customer Personal Data procure that it enters into an agreement incorporating the Standard Contractual Clauses with the Customer. and 5.2.4 provide to Customer for review such copies of the Contracted Processors' agreements with Subprocessors (which may be redacted to remove confidential commercial information not relevant to the requirements of this Addendum) as Customer may request from time to timeeach case without penalty. 5.3 SentinelOne shall ensure that each Subprocessor performs its obligations under sections 2.1, 3, 4, 6.1, 7.2, 8 and 10.1, as they apply to Processing of Customer Personal Data carried out by that Subprocessor, as if it were party to this Addendum in place of SentinelOne.

Appears in 1 contract

Sources: Data Processing Agreement

Subprocessing. 5.1 Customer authorises SentinelOne to appoint (8.1. The Controller specifically authorizes and permit generally agrees with the Provider and each Subprocessor appointed in accordance with this section 5 to appoint) Provider Affiliate appointing and engaging Subprocessors in accordance with this section 5 8 and any restrictions in the Agreement. 8.2. SentinelOne The Provider and each Provider Affiliate may also continue to use those Subprocessors already engaged by the Provider or any Provider Affiliate at the Start Date, whereby the Provider and Provider Affiliate shall make available be in each case and as soon as practicable required to Customer ensure that the current obligations set out in this section 8. are met by such Subprocessors. 8.3. The list of Subprocessors that are processing Customer Personal Data, attached as Annex 3. SentinelOne shall provide Customer prior written notice of the appointment of any new Subprocessor, including details of regarding their location and Processing functions is available here and may be updated from time to time by the Provider. 8.4. Regarding the Processing to be undertaken by the Subprocessor. If, within thirty (30) days and subprocessing of receipt of that notice, Customer notifies SentinelOne in writing of any objections to the proposed appointment, and further provides commercially reasonable justifications to such objections based on valid concerns regarding such proposed Subprocessor’s business practices relating to data protection, then (i) SentinelOne shall work with Customer in good faith to address Customer’s objections regarding the new Subprocessor; and (ii) where Customer’s concerns cannot be resolved within thirty (30) days from SentinelOne's receipt of Customer's notice, notwithstanding anything in the Agreement, Customer may, by providing SentinelOne with a written notice to with immediate effect, terminate the Agreement and SentinelOne shall refund to Customer all prepaid Fees for the Solutions attributable to the Subscription Term (as outlined in the applicable Purchase Order) following the termination of these Terms. 5.2 With respect to each Subprocessor, SentinelOne shall: 5.2.1 before the Subprocessor first Processes Customer Controller Personal Data, carry out adequate due diligence to ensure that the Provider and any Provider Affiliate shall only appoint and engage Subprocessor is capable through the conclusion of providing the level of a data processing agreement containing all necessary data protection for Customer Personal Data required by the Agreement; 5.2.2 ensure that the arrangement between on the one hand (a) SentinelOneobligations, or (b) the relevant intermediate Subprocessor; and on the other hand, the Subprocessor, is governed by a written contract including terms which shall offer at least the same level of data processing protection for Customer Personal Data as those set out that can be found in this Addendum and meet DPA, to the requirements of Article 28(3) extent applicable to the nature of the GDPR; 5.2.3 if that arrangement involves a Restricted Transfer, ensure that the Standard Contractual Clauses are at all relevant times incorporated into the agreement between on the one hand (a) SentinelOne, or (b) the relevant intermediate Subprocessor; and on the other hand the Subprocessor, or before the Subprocessor first Processes Customer Personal Data procure that it enters into an agreement incorporating the Standard Contractual Clauses with the Customer. and 5.2.4 provide to Customer for review Services provided by such copies of the Contracted Processors' agreements with Subprocessors (which may be redacted to remove confidential commercial information not relevant to the requirements of this Addendum) as Customer may request from time to timeSubprocessors. 5.3 SentinelOne shall ensure that each Subprocessor performs its obligations under sections 2.1, 3, 4, 6.1, 7.2, 8 and 10.1, as they apply 8.5. Ten (10) business days prior to any Processing of Customer Personal Data being carried out by that a newly appointed Subprocessor, the Provider shall add such newly engaged Subprocessor to the list of Subprocessors. The parties hereby agree that such method of notification is adequate with regards to the Controllers right to be notified prior to Subprocessor engagement. 8.6. Should the Controller or Controller Affiliate oppose the engagement and appointment of a new Subprocessor, he shall notify the Provider within ten (10) business days from the last day prior to the start of Processing as if it were party referred to in the previous point. After that, Processing by the Subprocessor shall be deemed as accepted by the Controller or Controller Affiliate. 8.7. Should the Controller or Controller Affiliate oppose the engagement and appointment of a new Subprocessor and notify the Provider regarding this Addendum (even after the period from the previous point), all data processing by such newly appointed Subprocessor shall cease and the parties shall seek to find an applicable solution in place of SentinelOnegood faith. If the parties cannot agree on an applicable solution regarding the objection in a reasonable timeframe, the Controller may terminate the Agreement. 8.8. The Provider may be held liable for all obligations subcontracted to the Subprocessors, including their acts and omissions.

Appears in 1 contract

Sources: Data Processing Agreement

Subprocessing. 5.1 Customer ‌ 6.1 Each Company Group Member authorises SentinelOne Vendor and each Vendor Affiliate to appoint (and permit each Subprocessor appointed in accordance with this section 5 6 to appoint) Subprocessors in accordance with this section 5 6 and any restrictions in the Principal Agreement. SentinelOne . 6.2 Vendor and each Vendor Affiliate may continue to use those Subprocessors already engaged by Vendor or any Vendor Affiliate as at the date of this Addendum, subject to Vendor and each Vendor Affiliate in each case as soon as practicable meeting the obligations set out in section 6.4.‌ 6.3 Vendor shall make available to Customer the current list of Subprocessors that are processing Customer Personal Data, attached as Annex 3. SentinelOne shall provide Customer give Company prior written notice of the appointment of any new Subprocessor, including full details of the Processing to be undertaken by the Subprocessor. If, within thirty (30) 30 days of receipt of that notice, Customer Company notifies SentinelOne Vendor in writing of any objections (on reasonable grounds) to the proposed appointment, and further provides commercially reasonable justifications to such objections based on valid concerns regarding such proposed Subprocessor’s business practices relating to data protection, then (i) SentinelOne shall work with Customer in good faith to address Customer’s objections regarding the new Subprocessor; and (ii) where Customer’s concerns cannot be resolved within thirty (30) days from SentinelOne's receipt of Customer's notice, notwithstanding anything in the Agreement, Customer may, by providing SentinelOne with a written notice to with immediate effect, terminate the Agreement and SentinelOne shall refund to Customer all prepaid Fees for the Solutions attributable to the Subscription Term (as outlined in the applicable Purchase Order) following the termination of these Terms.: 5.2 6.4 With respect to each Subprocessor, SentinelOne shall:Vendor or the relevant Vendor Affiliate shall:‌ 5.2.1 6.4.1 before the Subprocessor first Processes Customer Company Personal DataData (or, where relevant, in accordance with section 6.2), carry out adequate due diligence to ensure that the Subprocessor is capable of providing the level of protection for Customer Company Personal Data required by the Principal Agreement; 5.2.2 6.4.2 ensure that the arrangement between on the one hand (a) SentinelOneVendor, or (b) the relevant Vendor Affiliate, or (c) the relevant intermediate Subprocessor; and on the other hand, the Subprocessor, is governed by a written contract including terms which offer at least the same level of protection for Customer Personal Data as those set out in this Addendum and meet the requirements of Article 28(3) of the GDPR;on 5.2.3 6.4.3 if that arrangement involves a Restricted Transfer, ensure that the Standard Contractual Clauses are at all relevant times incorporated into the agreement between on the one hand hand (a) SentinelOneVendor, or (b) the relevant Vendor Affiliate, or (c) the relevant intermediate Subprocessor; and on the other hand the Subprocessor, or before the Subprocessor first Processes Customer Company Personal Data procure that it enters into an agreement incorporating the Standard Contractual Clauses with the Customer. andrelevant Company Group Member(s) (and Company shall procure that each Company Affiliate party to any such Standard Contractual Clauses co-operates with their population and execution); and‌ 5.2.4 6.4.4 provide to Customer Company for review such copies of the Contracted Processors' agreements with Subprocessors (which may be redacted to remove confidential commercial information not relevant to the requirements of this Addendum) as Customer Company may request from time to time. 5.3 SentinelOne 6.5 Vendor and each Vendor Affiliate shall ensure that each Subprocessor performs its the obligations under sections 2.1, 33.1, 4, 6.15, 7.27.1, 8 8.2, 9 and 10.111.1, as they apply to Processing of Customer Company Personal Data carried out by that Subprocessor, as if it were party to this Addendum in place of SentinelOneVendor.

Appears in 1 contract

Sources: Data Processing Addendum

Subprocessing. 5.1 6.1 Each Customer Group Member authorises SentinelOne Lineup and each Lineup Affiliate to appoint (and permit each Subprocessor appointed in accordance with this section 5 6 to appoint) Subprocessors in accordance with this section 5 6 and any restrictions in the Principal Agreement. SentinelOne . 6.2 Lineup and each Lineup Affiliate may continue to use those Subprocessors already engaged by Lineup or any Lineup Affiliate as at the date of these Data Processing Terms, subject to Lineup and each Lineup Affiliate in each case as soon as practicable meeting the obligations set out in section 6.4. 6.3 Lineup shall make available to Customer the current list of Subprocessors that are processing Customer Personal Data, attached as Annex 3. SentinelOne shall provide give Customer prior written notice of the appointment of any new Subprocessor, including full details of the Processing to be undertaken by the Subprocessor. If, within thirty (30) 30 days of receipt of that notice, Customer notifies SentinelOne Lineup in writing of any objections (on reasonable grounds) to the proposed appointment, and further provides commercially reasonable justifications to such objections based on valid concerns regarding such proposed Subprocessor’s business practices relating to data protection, then (i) SentinelOne : 6.3.1 Lineup shall work with Customer in good faith to address Customer’s objections regarding make available a commercially reasonable change in the new provision of the Services which avoids the use of that proposed Subprocessor; and (ii) and 6.3.2 where Customer’s concerns such a change cannot be resolved made within thirty (30) 180 days from SentinelOneLineup's receipt of Customer's notice, notwithstanding anything in the Principal Agreement, Customer may, may by providing SentinelOne with a written notice to Lineup with immediate effect, effect terminate the Principal Agreement and SentinelOne shall refund to Customer all prepaid Fees for the Solutions attributable to the Subscription Term (as outlined in extent that it relates to the applicable Purchase Order) following Services which require the termination use of these Termsthe proposed Subprocessor. 5.2 6.4 With respect to each Subprocessor, SentinelOne Lineup or the relevant Lineup Affiliate shall: 5.2.1 6.4.1 before the Subprocessor first Processes Customer Personal DataData (or, where relevant, in accordance with section 6.2), carry out adequate due diligence to ensure that the Subprocessor is capable of providing the level of protection for Customer Personal Data required by the Principal Agreement; 5.2.2 6.4.2 ensure that the arrangement between on the one hand (a) SentinelOneLineup, or (b) the relevant Lineup Affiliate, or (c) the relevant intermediate Subprocessor; and on the other hand, hand the Subprocessor, is governed by a written contract including terms which offer at least the same level of protection for Customer Personal Data as those set out in this Addendum these Data Processing Terms and meet the requirements of Article article 28(3) of the GDPR; 5.2.3 6.4.3 if that arrangement involves a Restricted Transfer, ensure that the Standard Contractual Clauses are at all relevant times incorporated into the agreement between on the one hand hand (a) SentinelOneLineup, or (b) the relevant Lineup Affiliate, or (c) the relevant intermediate Subprocessor; and on the other hand the Subprocessor, or before the Subprocessor first Processes Customer Personal Data procure that it enters into an agreement incorporating the Standard Contractual Clauses with the Customer. relevant Customer Group Member(s) (and Customer shall procure that each Customer Affiliate party to any such Standard Contractual Clauses co-operates with their population and execution); and 5.2.4 6.4.4 provide to Customer for review such copies of the Contracted Processors' agreements with Subprocessors (which may be redacted to remove confidential commercial information not relevant to the requirements of this Addendumthese Data Processing Terms) as Customer may request from time to time. 5.3 SentinelOne 6.5 Lineup and each Lineup Affiliate shall ensure that each Subprocessor performs its the obligations under sections 2.1, 33.1, 4, 6.15, 7.27.1, 8 8.2, 9 and 10.111.1, as they apply to Processing of Customer Personal Data carried out by that Subprocessor, as if it were party to this Addendum these Data Processing Terms in place of SentinelOneLineup.

Appears in 1 contract

Sources: Data Processing Agreement

Subprocessing. 5.1 Customer authorises SentinelOne Master Distributor authorizes TTI Success Insights to appoint (and permit each Subprocessor appointed in accordance with this section 5 to appoint) Subprocessors in accordance with this section 5 and any restrictions in the Master Distributor Agreement. SentinelOne . 5.2 TTI Success Insights may continue to use those Subprocessors already engaged by TTI Success Insights as at the date of this Addendum, subject to TTI Success Insights as soon as practicable meeting the obligations set out in section 5.4. 5.3 TTI Success Insights shall make available to Customer the current list of Subprocessors that are processing Customer Personal Data, attached as Annex 3. SentinelOne shall provide Customer give Master Distributor prior written notice of the appointment of any new Subprocessor, including full details of the Processing to be undertaken by the Subprocessor. If, within thirty (30) ten business days of receipt of that notice, Customer Master Distributor notifies SentinelOne TTI Success Insights in writing of any objections (on reasonable grounds) to the proposed appointment, and further provides commercially reasonable justifications to such objections based on valid concerns regarding such proposed Subprocessor’s business practices relating to data protection, then (i) SentinelOne : 5.3.1 TTI Success Insights shall work with Customer Master Distributor in good faith to address Customer’s objections regarding make available a commercially reasonable change in the new provision of the Services which avoids the use of that proposed Subprocessor; and (ii) and 5.3.2 where Customer’s concerns such a change cannot be resolved made within thirty (30) ten business days from SentinelOne's TTI Success Insights’ receipt of Customer's Master Distributor’s notice, notwithstanding anything in the Master Distributor Agreement, Customer may, Master Distributor may by providing SentinelOne with a written notice to TTI Success Insights with immediate effect, effect terminate the Master Distributor Agreement and SentinelOne shall refund to Customer all prepaid Fees for the Solutions attributable to the Subscription Term (as outlined in extent that it relates to the applicable Purchase Order) following Services which require the termination use of these Termsthe proposed Subprocessor. 5.2 5.4 With respect to each Subprocessor, SentinelOne TTI Success Insights shall: 5.2.1 5.4.1 before the Subprocessor first Processes Customer Master Distributor Personal DataData (or, where relevant, in accordance with section 5.2), carry out adequate due diligence to ensure that the Subprocessor is capable of providing the level of protection for Customer Master Distributor Personal Data required by the Master Distributor Agreement; 5.2.2 5.4.2 ensure that the arrangement between on the one hand (a) SentinelOne, TTI Success Insights or (b) the relevant intermediate Subprocessor; and on the other hand, hand the Subprocessor, is governed by a written contract including terms which offer at least the same level of protection for Customer Master Distributor Personal Data as those set out in this Addendum and meet the requirements of Article article 28(3) of the GDPR; 5.2.3 5.4.3 if that arrangement involves a Restricted TransferTransfer and to the extent no other means allows for the transfer, ensure that the Standard Contractual Clauses are at all relevant times incorporated into the agreement between on the one hand (a) SentinelOne, TTI Success Insights or (b) the relevant intermediate Subprocessor; and on the other hand the Subprocessor, or before the Subprocessor first Processes Customer Master Distributor Personal Data procure that it enters into an agreement incorporating the Standard Contractual Clauses with the Customer. relevant Master Distributor Agreement; and 5.2.4 5.4.4 provide to Customer Master Distributor for review such copies of the Contracted Processors' agreements with Subprocessors (which may be redacted to remove confidential commercial information not relevant to the requirements of this Addendum) as Customer Master Distributor may request from time to time. 5.3 SentinelOne 5.5 TTI Success Insights shall ensure that each Subprocessor performs its the obligations under sections 2.1, 3, 4, 6.1, 7.2, 8 and 8, 10.1, as they apply to Processing of Customer Master Distributor Personal Data carried out by that Subprocessor, as if it were party to this Addendum in place of SentinelOneTTI Success Insights.

Appears in 1 contract

Sources: Data Protection Addendum

Subprocessing. 5.1 Customer authorises SentinelOne Supplier agrees that any third- party subprocessor it appoints shall be bound to appoint the same standard of data protection provided for by this Agreement; and that Supplier will enter into agreements accordingly with its applicable subprocessors to give appropriate effect to the requirements in this DPA Controller agrees that Supplier may use any subprocessor listed in Annex B. Notwithstanding this, Controller consents to Supplier engaging new subprocessors (and permit each Subprocessor appointed in accordance with this section 5 including the replacement of existing ones) to appoint) Subprocessors in accordance with this section 5 and any restrictions in process the Agreement. SentinelOne shall make available to Customer the current list of Subprocessors that are processing Customer Personal Data, attached as Annex 3. SentinelOne shall provide Customer provided that: (i) Supplier provides at least 30 business days prior written notice of the appointment addition or replacement of any new Subprocessor, subprocessor (including details of the Processing processing it performs or will perform), which may be given by provided details of such addition or replacement to be undertaken by the Subprocessor. If, within thirty (30) days of receipt of that notice, Customer notifies SentinelOne in writing of any objections to the proposed appointment, and further provides commercially reasonable justifications to such objections based on valid concerns regarding such proposed Subprocessor’s business practices relating to data protection, then (i) SentinelOne shall work with Customer in good faith to address Customer’s objections regarding the new SubprocessorController; and (ii) where Customer’s concerns canSupplier imposes data protection terms on any Subpemrosesan: Pemasok setuju bahwa setiap subpemroses pihak ketiga yang ditunjuknya akan terikat dengan standar perlindungan data yang sama yang diberikan oleh Perjanjian ini; dan bahwa Pemasok akan mengadakan perjanjian sebagaimana mestinya dengan subpemrosesnya untuk menerapkan dengan tepat persyaratan di dalam DPA ini, Pengontrol setuju bahwa Pemasok dapat menggunakan subpemroses mana pun yang tercantum di Lampiran ▇. ▇▇▇▇▇pun demikian, Pengontrol menyetujui Pemasok melibatkan subpemroses baru (termasuk penggantian subpemroses yang sudah ada) untuk memproses Data Pribadi, asalkan: (i) Pemasok memberikan pemberitahuan minimal 30 hari kerja sebelum penambahan atau penggantian subpemroses (termasuk detail tentang pemrosesan yang dikerjakannya atau akan dikerjakannya), yang dapat diberikan dengan memberikan informasi subprocessor it appoints that protect the Personal Data to the same standard provided for by this DPA. If Controller refuses to consent to Supplier's appointment of a new third-party subprocessor, which should not be resolved within thirty (30) days from SentinelOne's receipt of Customer's noticewithheld unreasonably, notwithstanding anything in then either Supplier will not appoint the subprocessor or Controller may elect to terminate the Agreement, Customer may, by providing SentinelOne with a written notice to with immediate effect, terminate provided that the Agreement Controller has substantial and SentinelOne shall refund to Customer all prepaid Fees documented reasons for the Solutions attributable objection to the Subscription Term (as outlined in the applicable Purchase Order) following the termination of these Termschange. 5.2 With respect to each Subprocessor, SentinelOne shall: 5.2.1 before the Subprocessor first Processes Customer Personal Data, carry out adequate due diligence to ensure that the Subprocessor is capable of providing the level of protection for Customer Personal Data required by the Agreement; 5.2.2 ensure that the arrangement between on the one hand (a) SentinelOne, or (b) the relevant intermediate Subprocessor; and on the other hand, the Subprocessor, is governed by a written contract including terms which offer at least the same level of protection for Customer Personal Data as those set out in this Addendum and meet the requirements of Article 28(3) of the GDPR; 5.2.3 if that arrangement involves a Restricted Transfer, ensure that the Standard Contractual Clauses are at all relevant times incorporated into the agreement between on the one hand (a) SentinelOne, or (b) the relevant intermediate Subprocessor; and on the other hand the Subprocessor, or before the Subprocessor first Processes Customer Personal Data procure that it enters into an agreement incorporating the Standard Contractual Clauses with the Customer. and 5.2.4 provide to Customer for review such copies of the Contracted Processors' agreements with Subprocessors (which may be redacted to remove confidential commercial information not relevant to the requirements of this Addendum) as Customer may request from time to time. 5.3 SentinelOne shall ensure that each Subprocessor performs its obligations under sections 2.1, 3, 4, 6.1, 7.2, 8 and 10.1, as they apply to Processing of Customer Personal Data carried out by that Subprocessor, as if it were party to this Addendum in place of SentinelOne.

Appears in 1 contract

Sources: Data Processor Agreement

Subprocessing. 5.1 Customer authorises SentinelOne 7.1 Vendor and each Vendor Affiliate shall not engage Subprocessors acting as a Company’s 7.2 Vendor and each Vendor Affiliate may continue to appoint (use those Subprocessors already engaged by Vendor or any Vendor Affiliate as at the date of this Addendum, subject to Vendor and permit each Subprocessor appointed Vendor Affiliate in accordance with this each case as soon as practicable meeting the obligations set out in section 5 to appoint) Subprocessors in accordance with this section 5 and any restrictions in the Agreement. SentinelOne 7.4. 7.3 Vendor shall make available to Customer the current list of Subprocessors that are processing Customer Personal Data, attached as Annex 3. SentinelOne shall provide Customer give Company prior written notice of the appointment of any new Subprocessor, including full details of the Processing to be undertaken by the Subprocessor. If, within thirty (30) 30 days of receipt of that notice, Customer Company notifies SentinelOne Vendor in writing of any objections (on reasonable grounds) to the proposed appointment, and further provides commercially reasonable justifications to such objections based on valid concerns regarding such proposed Subprocessor’s business practices relating to data protection, then (i) SentinelOne : 7.3.1 Vendor shall work with Customer Company in good faith to address Customer’s objections regarding make available a commercially reasonable change in the new provision of the Services which avoids the use of that proposed Subprocessor; and (ii) and 7.3.2 where Customer’s concerns such a change cannot be resolved made within thirty (30) 30 days from SentinelOneVendor's receipt of CustomerCompany's notice, notwithstanding anything in the Principal Agreement, Customer may, Company may by providing SentinelOne with a written notice to Vendor with immediate effect, effect terminate the Principal Agreement and SentinelOne shall refund to Customer all prepaid Fees for the Solutions attributable to the Subscription Term (as outlined in extent that it relates to the applicable Purchase Order) following Services which require the termination use of these Termsthe proposed Subprocessor. 5.2 7.4 With respect to each Subprocessor, SentinelOne Vendor or the relevant Vendor Affiliate shall: 5.2.1 7.4.1 before the Subprocessor first Processes Customer Company Personal DataData (or, where relevant, in accordance with section 7.2), carry out adequate due diligence to ensure that the Subprocessor is capable of providing the level of protection for Customer Company Personal Data required by the Principal Agreement; 5.2.2 7.4.2 ensure that the arrangement between on the one hand (a) SentinelOneVendor, or (b) the relevant Vendor Affiliate, or (c) the relevant intermediate Subprocessor; and on the other hand, the Subprocessor, is governed by a written contract including terms which offer at least the same level of protection for Customer Company Personal Data as those set out in this Addendum and meet the requirements of Article article 28(3) of the GDPR; 5.2.3 if that arrangement involves a Restricted Transfer, ensure that the Standard Contractual Clauses are at all relevant times incorporated into the agreement between on the one hand (a) SentinelOne, or (b) the relevant intermediate Subprocessor; and on the other hand the Subprocessor, or before the Subprocessor first Processes Customer Personal Data procure that it enters into an agreement incorporating the Standard Contractual Clauses with the Customer. and 5.2.4 7.4.3 provide to Customer Company for review such copies of the Contracted Processors' agreements with Subprocessors (which may be redacted to remove confidential commercial information not relevant to the requirements of this Addendum) as Customer Company may request from time to time. 5.3 SentinelOne 7.4.4 maintain an up-to-date list of Subprocessors (see Annex 4) specifying (i) their name and details, as well as (ii) the nature of the tasks entrusted to them, (iii) the location of the Processing and (iv) the dates of previous audits. 7.5 Vendor and each Vendor Affiliate shall ensure that each Subprocessor performs its the obligations under sections 2.14.1, 35, 46.1.5, 6.18.1, 7.29, 8 10, 11 and 10.112.1, as they apply to Processing of Customer Company Personal Data carried out by that Subprocessor, as if it were party to this Addendum in place of SentinelOneVendor. Vendor will remain responsible for its compliance with the obligations of this Addendum and for any acts or omissions of the Subprocessor that cause Vendor to breach any of Vendor’s obligations under this Addendum.

Appears in 1 contract

Sources: Data Processing Addendum

Subprocessing. 5.1 11.1 Customer authorises SentinelOne authorizes 5thPort to appoint (and permit each Subprocessor appointed in accordance with this section 5 11 to appoint) Subprocessors in accordance with this section 5 11 and any restrictions in the Agreement. SentinelOne SA. 11.2 5thPort may continue to use those Subprocessors already engaged by 5thPort as of the date of this Addendum, subject to 5thPort as soon as practicable meeting the obligations set out in section 11.4. 11.3 5thPort shall make available to Customer the current list of Subprocessors that are processing Customer Personal Data, attached as Annex 3. SentinelOne shall provide give Customer prior written notice of the appointment of any new Subprocessor, including details of the Processing to be undertaken by the Subprocessor. If, within thirty fourteen (3014) days of receipt of that notice, Customer notifies SentinelOne 5thPort in writing of any objections (on reasonable grounds to the proposed appointment), 5thPort shall not appoint that proposed Subprocessor until reasonable steps have been taken to address the objections raised by Customer, and further provides commercially reasonable justifications to such objections based on valid concerns regarding such proposed Subprocessor’s business practices relating to data protection, then (i) SentinelOne shall work with Customer in good faith to address Customer’s objections regarding the new Subprocessor; and (ii) where Customer’s concerns cannot be resolved within thirty (30) days from SentinelOne's receipt of Customer's notice, notwithstanding anything in the Agreement, Customer may, by providing SentinelOne has been provided with a reasonable written notice to with immediate effect, terminate explanation of the Agreement and SentinelOne shall refund to Customer all prepaid Fees for the Solutions attributable to the Subscription Term (as outlined in the applicable Purchase Order) following the termination of these Termssteps taken. 5.2 11.4 With respect to each Subprocessor, SentinelOne 5thPort shall: 5.2.1 11.4.1 before the Subprocessor first Processes Customer Personal DataData (or, where relevant, in accordance with section 11.2), carry out adequate due diligence to ensure that the Subprocessor is capable of providing the level of protection for Customer Personal Data required by the AgreementSA; 5.2.2 11.4.2 ensure that the arrangement between between, on the one hand 5thPort (a) SentinelOne, or (b) the relevant an intermediate Subprocessor; and ) and, on the other hand, the Subprocessor, is governed by a written contract including terms which offer at least the same level of protection for Customer Personal Data as those set out in this Addendum and meet the requirements of Article 28(3) of the GDPR; 5.2.3 11.4.3 if that arrangement involves a Restricted Transfertransfer of Customer Personal Data, ensure that the Standard Contractual Clauses Subprocessor take all such measures as are at all relevant times incorporated into the agreement between on the one hand (a) SentinelOne, or (b) the relevant intermediate Subprocessorreasonably required to ensure such transfer is in compliance with any applicable Data Protection Laws; and on the other hand the Subprocessor, or before the Subprocessor first Processes Customer Personal Data procure that it enters into an agreement incorporating the Standard Contractual Clauses with the Customer. and 5.2.4 11.4.4 provide to Customer for review such copies of the Contracted Processors' 5thPort’s agreements with Subprocessors (which may be redacted to remove confidential commercial information not relevant to the requirements of this Addendum) as Customer may request from time to time. 5.3 SentinelOne 11.5 5thPort shall ensure that each Subprocessor performs its obligations under sections 2.1, 3, 4, 6.1, 7.2, 8 and 10.1, as they apply to Processing of Customer Personal Data carried out by that SubprocessorData, as if it the Subprocessor were party to this Addendum in place of SentinelOne5thPort.

Appears in 1 contract

Sources: Service Agreement

Subprocessing. 5.1 Customer 6.1 Each Company Group Member authorises SentinelOne Vendor and each Vendor Affiliate to appoint (and permit each Subprocessor appointed in accordance with this section 5 6 to appoint) Subprocessors in accordance with this section 5 6 and any restrictions in the Principal Agreement. SentinelOne . 6.2 Vendor and each Vendor Affiliate may continue to use those Subprocessors already engaged by Vendor or any Vendor Affiliate as at the date of this Addendum, subject to Vendor and each Vendor Affiliate in each case as soon as practicable meeting the obligations set out in section 6.4. 6.3 Vendor shall make available to Customer the current list of Subprocessors that are processing Customer Personal Data, attached as Annex 3. SentinelOne shall provide Customer give Company prior written notice of the appointment of any new Subprocessor, including full details of the Processing to be undertaken by the Subprocessor. If, within thirty (30) days of receipt of that notice, Customer If Company notifies SentinelOne Vendor in writing of any objections (on reasonable grounds) to the proposed appointment, and further provides commercially reasonable justifications to such objections based on valid concerns regarding such : Neither Vendor nor any Vendor Affiliate shall appoint (nor disclose any Company Personal Data to) the proposed Subprocessor’s business practices relating to data protection, then (i) SentinelOne shall work Subprocessor except with Customer in good faith to address Customer’s objections regarding the new Subprocessor; and (ii) where Customer’s concerns cannot be resolved within thirty (30) days from SentinelOne's receipt prior written consent of Customer's notice, notwithstanding anything in the Agreement, Customer may, by providing SentinelOne with a written notice to with immediate effect, terminate the Agreement and SentinelOne shall refund to Customer all prepaid Fees for the Solutions attributable to the Subscription Term (as outlined in the applicable Purchase Order) following the termination of these TermsCompany. 5.2 6.4 With respect to each Subprocessor, SentinelOne Vendor or the relevant Vendor Affiliate shall: 5.2.1 6.4.1 before the Subprocessor first Processes Customer Company Personal DataData (or, where relevant, in accordance with section 6.2), carry out adequate due diligence to ensure that the Subprocessor is capable of providing can provide the level of protection for Customer Company Personal Data required by the Principal Agreement; 5.2.2 6.4.2 ensure that the arrangement between on the one hand (a) SentinelOneVendor, or (b) the relevant Vendor Affiliate, or (c) the relevant intermediate Subprocessor; and on the other hand, the Subprocessor, is governed by a written contract including terms which offer at least the same level of protection for Customer Company Personal Data as those set out in this Addendum and meet the requirements of Article article 28(3) of the GDPR; 5.2.3 6.4.3 if that arrangement involves a Restricted Transfer, ensure that the Standard Contractual Clauses are at all relevant times incorporated into the agreement between on the one hand hand (a) SentinelOneVendor, or (b) the relevant Vendor Affiliate, or (c) the relevant intermediate Subprocessor; and on the other hand the Subprocessor, or before the Subprocessor first Processes Customer Company Personal Data procure that it enters into an agreement incorporating the Standard Contractual Clauses with the Customer. relevant Company Group Member(s) (and Company shall procure that each Company Affiliate party to any such Standard Contractual Clauses co-operates with their population and execution); and 5.2.4 6.4.4 provide to Customer Company for review such copies of the Contracted Processors' agreements with Subprocessors (which may be redacted to remove confidential commercial information not relevant to the requirements of this Addendum) as Customer Company may request from time to time. 5.3 SentinelOne 6.5 Vendor and each Vendor Affiliate shall ensure that each Subprocessor performs its the obligations under sections 2.1, 33.1, 4, 6.15, 7.27.1, 8 8.2, 9 and 10.111.1, as they apply to Processing of Customer Company Personal Data carried out by that Subprocessor, as if it were party to this Addendum in place of SentinelOneVendor.

Appears in 1 contract

Sources: Data Protection Addendum

Subprocessing. 5.1 Customer ‌ 6.1 Each Company Group Member authorises SentinelOne Vendor and each Vendor Affiliate to appoint (and permit each Subprocessor appointed in accordance with this section 5 6 to appoint) Subprocessors in accordance with this section 5 6 and any restrictions in the Principal Agreement. SentinelOne . 6.2 Vendor and each Vendor Affiliate may continue to use those Subprocessors already engaged by Vendor or any Vendor Affiliate as at the date of this Addendum, subject to Vendor and each Vendor Affiliate in each case as soon as practicable meeting the obligations set out in section 6.4.‌ 6.3 Vendor shall make available to Customer the current list of Subprocessors that are processing Customer Personal Data, attached as Annex 3. SentinelOne shall provide Customer give Company prior written notice of the appointment of any new Subprocessor, including full details of the Processing to be undertaken by the Subprocessor. If, within thirty (30) 30 days of receipt of that notice, Customer Company notifies SentinelOne Vendor in writing of any objections (on reasonable grounds) to the proposed appointment, and further provides commercially reasonable justifications to such objections based on valid concerns regarding such proposed Subprocessor’s business practices relating to data protection, then (i) SentinelOne : 6.3.1 Vendor shall work with Customer Company in good faith to address Customer’s objections regarding make available a commercially reasonable change in the new provision of the Services which avoids the use of that proposed Subprocessor; and (ii) and 6.3.2 where Customer’s concerns such a change cannot be resolved made within thirty (30) 30 days from SentinelOneVendor's receipt of CustomerCompany's notice, notwithstanding anything in the Principal Agreement, Customer may, Company may by providing SentinelOne with a written notice to Vendor with immediate effect, effect terminate the Principal Agreement and SentinelOne shall refund to Customer all prepaid Fees for the Solutions attributable to the Subscription Term (as outlined in extent that it relates to the applicable Purchase Order) following Services which require the termination use of these Termsthe proposed Subprocessor. 5.2 6.4 With respect to each Subprocessor, SentinelOne shall:Vendor or the relevant Vendor Affiliate shall:‌ 5.2.1 6.4.1 before the Subprocessor first Processes Customer Company Personal DataData (or, where relevant, in accordance with section 6.2), carry out adequate due diligence to ensure that the Subprocessor is capable of providing the level of protection for Customer Company Personal Data required by the Principal Agreement; 5.2.2 6.4.2 ensure that the arrangement between on the one hand (a) SentinelOneVendor, or (b) the relevant Vendor Affiliate, or (c) the relevant intermediate Subprocessor; and on the other hand, hand the Subprocessor, is governed by a written contract including terms which offer at least the same level of protection for Customer Company Personal Data as those set out in this Addendum and meet the requirements of Article article 28(3) of the GDPR; 5.2.3 6.4.3 if that arrangement involves a Restricted Transfer, ensure that the Standard Contractual Clauses are at all relevant times incorporated into the agreement between on the one hand hand (a) SentinelOneVendor, or (b) the relevant Vendor Affiliate, or (c) the relevant intermediate Subprocessor; and on the other hand the Subprocessor, or before the Subprocessor first Processes Customer Company Personal Data procure that it enters into an agreement incorporating the Standard Contractual Clauses with the Customer. andrelevant Company Group Member(s) (and Company shall procure that each Company Affiliate party to any such Standard Contractual Clauses co-operates with their population and execution); and‌ 5.2.4 6.4.4 provide to Customer Company for review such copies of the Contracted Processors' agreements with Subprocessors (which may be redacted to remove confidential commercial information not relevant to the requirements of this Addendum) as Customer Company may request from time to time. 5.3 SentinelOne 6.5 Vendor and each Vendor Affiliate shall ensure that each Subprocessor performs its the obligations under sections 2.1, 33.1, 4, 6.15, 7.27.1, 8 8.2, 9 and 10.111.1, as they apply to Processing of Customer Company Personal Data carried out by that Subprocessor, as if it were party to this Addendum in place of SentinelOneVendor.

Appears in 1 contract

Sources: Data Processing Agreement

Subprocessing. 5.1 Customer ‌ 6.1 Each Subscriber Group Member authorises SentinelOne Vena and each Vena Affiliate to appoint (Subprocessors subject to this clause 6, and permit each Subprocessor appointed in accordance with this section 5 to appoint) Subprocessors in accordance with this section 5 and any restrictions in the Agreement. SentinelOne shall make available to Customer the current list of Subprocessors that are processing Customer Personal Data, attached as Annex 3. SentinelOne shall provide Customer prior written notice of authorises the appointment of the Subprocessors listed at ▇▇▇▇▇://▇▇▇.▇▇▇▇▇▇▇▇▇▇▇▇▇.▇▇▇/sub-processors. 6.2 Before appointing any new additional Subprocessor, including details of Vena or the Processing to be undertaken by the Subprocessor. If, within thirty (30) days of receipt of that notice, Customer notifies SentinelOne in writing of any objections to the proposed appointment, and further provides commercially reasonable justifications to such objections based on valid concerns regarding such proposed Subprocessor’s business practices relating to data protection, then (i) SentinelOne shall work with Customer in good faith to address Customer’s objections regarding the new Subprocessor; and (ii) where Customer’s concerns cannot be resolved within thirty (30) days from SentinelOne's receipt of Customer's notice, notwithstanding anything in the Agreement, Customer may, by providing SentinelOne with a written notice to with immediate effect, terminate the Agreement and SentinelOne shall refund to Customer all prepaid Fees for the Solutions attributable to the Subscription Term (as outlined in the applicable Purchase Order) following the termination of these Terms. 5.2 With respect to each Subprocessor, SentinelOne relevant Vena Affiliate shall: 5.2.1 before the Subprocessor first Processes Customer Personal Data, 6.2.1 carry out adequate due diligence to ensure that the Subprocessor is capable of providing can provide the level of protection for Customer Subscriber Personal Data required by the AgreementPrincipal Agreement and this Addendum; 5.2.2 6.2.2 ensure that the arrangement between between, on the one hand (a) SentinelOneVena, (b) the relevant Vena Affiliate, or (bc) the relevant intermediate Subprocessor; and and, on the other hand, the proposed Subprocessor, is governed by a written contract including terms which offer that imposes on such proposed Subprocessor at least (x) the same level of protection for Customer Subscriber Personal Data as those set out in this Addendum Addendum, and meet (y) the requirements of Article 28(3) of the GDPRprotections required by Applicable Laws (“Subprocessor DPA”); 5.2.3 if that arrangement involves a Restricted Transfer6.2.3 notify the Subscriber at least 10 days ahead of such appointment, ensure that the Standard Contractual Clauses are at all relevant times incorporated into the agreement between on the one hand (a) SentinelOnemaking available to it for good-faith, or (b) the relevant intermediate Subprocessor; and on the other hand the Subprocessor, or before confidential review the Subprocessor first Processes Customer Personal Data procure that it enters into an agreement incorporating the Standard Contractual Clauses with the Customer. and 5.2.4 provide to Customer for review such copies of the Contracted Processors' agreements with Subprocessors DPA (which may be redacted to remove confidential commercial information not relevant to the requirements of this Addendum) as Customer may request from time to timeupon request. 5.3 SentinelOne 6.3 In the event that Subscriber objects to the appointment of such Subprocessor within two weeks of receiving such notice, 6.3.1 Vena shall work with Subscriber in good faith to make available a commercially reasonable change in the provision of the Services which avoids the use of that proposed Subprocessor; and 6.3.2 where such a change cannot be made within 90 days from Vena’s receipt of Subscriber’s notice, notwithstanding anything in the Principal Agreement, Subscriber may in good faith, by written notice to Vena with immediate effect, terminate the Principal Agreement. 6.4 Vena and each Vena Affiliate 6.4.1 shall ensure that each Subprocessor performs its the obligations under sections 2.1, 33.1, 4, 6.15, 7.27.1, 8 8.2, 9 and 10.111.1, as they apply to Processing of Customer Subscriber Personal Data carried out by that Subprocessor, as if it were party to this Addendum in place of SentinelOneVena, and 6.4.2 acknowledges that where a Subprocessor fails to fulfil its data protection obligations Vena or the Vena Affiliate remains, as between it and Subscriber, fully liable to Subscriber for the performance of such obligations.

Appears in 1 contract

Sources: Data Protection Addendum

Subprocessing. 5.1 Customer authorises SentinelOne 7.1 Each Company Group Member authorizes each Ooyala Group Member to appoint (and permit each Subprocessor appointed in accordance with this section 5 6 to appoint) Subprocessors in accordance with this section 5 6 and any restrictions in the Agreement. SentinelOne . 7.2 Ooyala Group Members may continue to use those Subprocessors already engaged by an Ooyala Group Member as at the date of this DPA, subject to the Ooyala Group Member in each case meeting the obligations set out in section 7.4. 7.3 Ooyala shall make available to Customer the current list of Subprocessors that are processing Customer Personal Data, attached as Annex 3. SentinelOne shall provide Customer give Company prior written notice of the appointment of any new Subprocessor, including full details of the Processing to be undertaken by the Subprocessor. If, within thirty (30) days of receipt of that notice, Customer Company notifies SentinelOne Vendor in writing of any objections (on reasonable grounds) to the proposed appointment, and further provides commercially reasonable justifications to such objections based on valid concerns regarding such proposed Subprocessor’s business practices relating to data protection, then (i) SentinelOne Ooyala shall work with Customer Company in good faith to address Customer’s objections regarding make available a commercially reasonable change in the new provision of the Services which avoids the use of that proposed Subprocessor; and (ii) and, where Customer’s concerns such a change cannot be resolved made within thirty ninety (3090) days from SentinelOneOoyala's receipt of CustomerCompany's notice, notwithstanding anything in the Agreement, Customer may, Company may by providing SentinelOne with a written notice to Ooyala with immediate effect, effect terminate the Agreement and SentinelOne shall refund to Customer all prepaid Fees for the Solutions attributable to the Subscription Term (as outlined in extent that it relates to the applicable Purchase Order) following Services which require the termination use of these Termsthe proposed Subprocessor. 5.2 7.4 With respect to each Subprocessor, SentinelOne shall:Ooyala or the relevant Ooyala Affiliate shall:‌ 5.2.1 (a) before the Subprocessor first Processes Customer Company Personal Data, carry out adequate due diligence to ensure that the Subprocessor is capable of providing the level of protection for Customer Company Personal Data required by the Agreement; 5.2.2 (b) ensure that the arrangement between on the one hand (a) SentinelOnethe Ooyala Group Member, or (b) the relevant intermediate Subprocessor; and on the other hand, the Subprocessor, is governed by a written contract including terms which offer at least the same level of protection for Customer Personal Data as those set out in this Addendum and meet the requirements of Article 28(3) of the GDPR; 5.2.3 if that arrangement involves a Restricted Transfer, ensure that the Standard Contractual Clauses are at all relevant times incorporated into the agreement between on the one hand (a) SentinelOne, or (b) the relevant intermediate Subprocessor; and on the other hand the Subprocessor, or before the Subprocessor first Processes Customer Personal Data procure that it enters into an agreement incorporating the Standard Contractual Clauses with the Customer. and 5.2.4 provide to Customer for review such copies of the Contracted Processors' agreements with Subprocessors (which may be redacted to remove confidential commercial information not relevant to the requirements of this Addendum) as Customer may request from time to time. 5.3 SentinelOne shall ensure that each Subprocessor performs its obligations under sections 2.1, 3, 4, 6.1, 7.2, 8 and 10.1, as they apply to Processing of Customer Personal Data carried out by that Subprocessor, as if it were party to this Addendum in place of SentinelOne.on

Appears in 1 contract

Sources: Data Processing Addendum

Subprocessing. 5.1 Customer authorises SentinelOne to Neither Vendor nor any Vendor Affiliate shall appoint (and permit each nor disclose any Company Personal Data to) the proposed Subprocessor appointed in accordance except with this section 5 to appoint) Subprocessors in accordance with this section 5 and any restrictions in the Agreement. SentinelOne shall make available to Customer the current list of Subprocessors that are processing Customer Personal Data, attached as Annex 3. SentinelOne shall provide Customer prior written notice consent of the appointment of any new Subprocessor, including details of the Processing to be undertaken by the Subprocessor. If, within thirty (30) days of receipt of that notice, Customer notifies SentinelOne in writing of any objections to the proposed appointment, and further provides commercially reasonable justifications to such objections based on valid concerns regarding such proposed Subprocessor’s business practices relating to data protection, then (i) SentinelOne shall work with Customer in good faith to address Customer’s objections regarding the new Subprocessor; and (ii) where Customer’s concerns cannot be resolved within thirty (30) days from SentinelOne's receipt of Customer's notice, notwithstanding anything in the Agreement, Customer may, by providing SentinelOne with a written notice to with immediate effect, terminate the Agreement and SentinelOne shall refund to Customer all prepaid Fees for the Solutions attributable to the Subscription Term (as outlined in the applicable Purchase Order) following the termination of these TermsCompany. 5.2 6.1 With respect to each Subprocessor, SentinelOne Vendor or the relevant Vendor Affiliate shall: 5.2.1 6.1.1 before the Subprocessor first Processes Customer Company Personal DataData (or, where relevant, in accordance with section 6.2), carry out adequate due diligence to ensure that the Subprocessor is capable of providing the level of protection for Customer Company Personal Data required by the Principal Agreement; 5.2.2 6.1.2 ensure that the arrangement between on the one hand (a) SentinelOneVendor, or (b) the relevant Vendor Affiliate, or (c) the relevant intermediate Subprocessor; and on the other hand, hand the Subprocessor, is governed by a written contract including terms 12 As the GDPR imposes on Vendor a requirement to ensure that appropriate security measures are in place, and Vendor may not be in a position to assess what measures are appropriate to the Company Personal Data (since the data are collected and processed for the purposes of Company's and not Vendor's business), Vendor may seek protection against contracted security measures turning out not to be appropriate although they have been approved (and may even have been specifically selected) by Company. It may also be the case that specific security measures are identified in the Principal Agreement. The GDPR does not (or at least does not clearly) change the actual standard of security required. The Company as Controller may wish to elaborate on the approach taken here, for example by: • committing Vendor only to a specific, relatively basic, level of security, described (in generic terms) in an Annex, with Company taking responsibility for any higher level of security required by the GDPR except to the extent specifically agreed (including in the Principal Agreement); or • confirming that Company has assessed any security measures specifically agreed in the Principal Agreement and that the Company is responsible (as between the parties and to data subjects and supervisory authorities) if those measures, in themselves (but acknowledging that any pre-agreed description may only deal with specific aspects of the required security arrangements rather than describing a comprehensive solution), do not meet the GDPR standard of appropriateness. which offer at least the same level of protection for Customer Company Personal Data as those set out in this Addendum and meet the requirements of Article article 28(3) of the GDPR;GDPR;13 5.2.3 6.1.3 if that arrangement involves a Restricted Transfer, ensure that the Standard Contractual Clauses are at all relevant times incorporated into the agreement between on the one hand hand (a) SentinelOneVendor, or (b) the relevant Vendor Affiliate, or (c) the relevant intermediate Subprocessor; and on the other hand the Subprocessor, or before the Subprocessor first Processes Customer Company Personal Data procure that it enters into an agreement incorporating the Standard Contractual Clauses with the Customer. relevant Company Group Member(s) (and Company shall procure that each Company Affiliate party to any such Standard Contractual Clauses co-operates with their population and execution);14 and 5.2.4 6.1.4 provide to Customer Company for review such copies of the Contracted Processors' agreements with Subprocessors (which may be redacted to remove confidential commercial information not relevant to the requirements of this Addendum) as Customer Company may request from time to time. 5.3 SentinelOne 6.2 Vendor and each Vendor Affiliate shall ensure that each Subprocessor performs its the obligations under sections 2.1, 33.1, 4, 6.15, 7.27.1, 8 8.2, 9 and 10.111.1, as they apply to Processing of Customer Company Personal Data carried out by that Subprocessor, as if it were party to this Addendum in place of SentinelOneVendor.

Appears in 1 contract

Sources: Data Protection Addendum

Subprocessing. 5.1 6.1 Customer authorises SentinelOne PeopleFluent to appoint (and permit each Subprocessor appointed in accordance with this section 5 6 to appoint) Subprocessors in accordance with this section 5 6 and any restrictions in the Agreement. SentinelOne . 6.2 PeopleFluent may continue to use those Subprocessors already engaged by PeopleFluent as at the date of this Exhibit, subject to PeopleFluent meeting the obligations set out in section 6.5. 6.3 PeopleFluent shall make available to Customer the current list of Subprocessors that are processing Customer Personal Data, attached as Annex 3. SentinelOne shall provide give Customer prior written notice of the appointment of any new Subprocessor, including full details of the Processing to be undertaken by the Subprocessor. If, within thirty (30) 7 days of receipt of that notice, Customer notifies SentinelOne PeopleFluent in writing of any objections (on reasonable grounds) to the proposed appointment, and further provides commercially reasonable justifications to such objections based on valid concerns regarding such proposed Subprocessor’s business practices relating to data protection, then (i) SentinelOne : 6.3.1 PeopleFluent shall work with Customer in good faith to address Customer’s objections regarding make available a commercially reasonable change in the new provision of the Services which avoids the use of that proposed Subprocessor; and (ii) and 6.3.2 where Customer’s concerns such a change cannot be resolved made within thirty (30) 45 days from SentinelOnePeopleFluent's receipt of Customer's notice, notwithstanding anything in the Agreement, Customer may, may by providing SentinelOne with a written notice to PeopleFluent with immediate effecteffect terminate the impacted services to the extent that it relates to the Services which require the use of the proposed Subprocessor. 6.4 On termination of the impacted services, terminate pursuant to section 6.3.2, Customer shall be liable for any contracted fees or charges for the remainder of the term of the Agreement and SentinelOne shall refund to Customer all prepaid Fees for the Solutions attributable to the Subscription Term (as outlined in the applicable Purchase Order) following the termination of these Termsany Order Forms thereunder. 5.2 6.5 With respect to each Subprocessor, SentinelOne PeopleFluent shall: 5.2.1 6.5.1 before the Subprocessor first Processes Customer Personal DataData (or, where relevant, in accordance with section 6.2), carry out adequate due diligence to ensure that the Subprocessor is capable of providing the level of protection for Customer Personal Data required by the Agreement; 5.2.2 6.5.2 ensure that the arrangement between on the one hand (a) SentinelOnePeopleFluent, or (b) the relevant intermediate Subprocessor; and on the other hand, hand the Subprocessor, is governed by a written contract including terms which offer at least the same level of protection for Customer Personal Data as those set out in this Addendum Exhibit and meet the requirements of Article 28(3) of the GDPR; 5.2.3 if that arrangement involves a Restricted Transfer, ensure that the Standard Contractual Clauses are at all relevant times incorporated into the agreement between on the one hand (a) SentinelOne, or (b) the relevant intermediate Subprocessor; and on the other hand the Subprocessor, or before the Subprocessor first Processes Customer Personal Data procure that it enters into an agreement incorporating the Standard Contractual Clauses with the Customer. and 5.2.4 6.5.3 provide to Customer for review such copies of the Contracted Processors' agreements with Subprocessors (which may be redacted to remove confidential commercial information not relevant to the requirements of this AddendumExhibit) as Customer may request from time to time. 5.3 SentinelOne 6.6 PeopleFluent shall ensure that each Subprocessor performs its the obligations under sections 2.1, 33.1, 4, 6.15, 7.27.1, 8 8.2, 9 and 10.111.1, as they apply to Processing of Customer Personal Data carried out by that Subprocessor, as if it were party to this Addendum Exhibit in place of SentinelOnePeopleFluent.

Appears in 1 contract

Sources: Service Agreement

Subprocessing. 5.1 Customer authorises SentinelOne 4.1 Subprocessing for the purpose of this Agreement is to appoint (be understood as meaning processing which relates directly to the Services provided to you. This does not include ancillary services commissioned by us, such as telecommunication services, postal / transport services, cleaning or guarding services. IT services shall constitute a Subprocessing relationship if they are provided for IT systems which are used for the delivery of the Services you have purchased from us. We shall, however, be obliged to make appropriate and permit each Subprocessor appointed legally binding contractual arrangements including technical and organizational measures and take appropriate inspection measures to ensure the data protection and the data security of your data, even in the case of outsourced ancillary services. 4.2 In accordance with the provisions of this section 5 Agreement, you acknowledge and agree that ▇▇▇▇▇▇, or the third parties engaged to appointprovide the Services provided here: ▇▇▇▇▇://▇▇▇▇▇▇.▇▇▇▇▇▇.▇▇▇/asset_ mgr/current/202114/Subprocessor%20List_LOr3.pdf (which are hereby designated as subprocessors for the purpose of processing Customer Data) Subprocessors may store or process Customer Data in accordance with this section 5 and any restrictions locations outside the country in which you are located on servers based in the Agreement. SentinelOne United States provided that (a) we shall make available publish notification of any changes to Customer the current list of Subprocessors that are subprocessors processing Customer Personal Data, attached as Annex 3. SentinelOne shall provide Customer prior written notice of the appointment of any new Subprocessor, including details of the Processing to be undertaken by the Subprocessor. If, within Data on our website thirty (30) days of receipt of that notice, Customer notifies SentinelOne in writing of prior to any objections changes to the proposed appointment, subprocessors processing Customer Data and further provides commercially give you an opportunity to review such changes and raise reasonable justifications objection to such objections based on valid concerns regarding such proposed Subprocessor’s business practices relating to data protection, then (i) SentinelOne shall work with Customer in good faith to address Customer’s objections regarding the new Subprocessorchanges; and (ii) where Customer’s concerns cannot be resolved within thirty (30) days from SentinelOne's receipt of Customer's notice, notwithstanding anything in the Agreement, Customer may, by providing SentinelOne with a written notice to with immediate effect, terminate the Agreement and SentinelOne shall refund to Customer all prepaid Fees for the Solutions attributable to the Subscription Term (as outlined in the applicable Purchase Order) following the termination of these Terms. 5.2 With respect to each Subprocessor, SentinelOne shall: 5.2.1 before the Subprocessor first Processes Customer Personal Data, carry out adequate due diligence to ensure that the Subprocessor is capable of providing the level of protection for Customer Personal Data required by the Agreement; 5.2.2 ensure that the arrangement between on the one hand (a) SentinelOne, or (b) the relevant intermediate Subprocessor; and on subprocessors processing Customer Data are subject to the other hand, the Subprocessor, is governed by a written contract including terms which offer at least same data protection obligations or the same level of protection for Customer Personal Data as those set out are contained in this Addendum and meet Agreement in accordance with Article 28 paragraphs 2-4 GDPR. Customer agrees to raise any reasonable objections in writing within ten (10) calendar days of such notification. In the requirements event you reasonably object to the addition of Article 28(3) of a Subprocessor for reasons related to the GDPR; 5.2.3 if that arrangement involves , as permitted in the preceding sentences, and the Parties do not find a Restricted Transfer, ensure that the Standard Contractual Clauses are at all relevant times incorporated into the agreement between on the one hand (a) SentinelOne, or (b) the relevant intermediate Subprocessor; and on the other hand the Subprocessor, or before the Subprocessor first Processes Customer Personal Data procure that it enters into an agreement incorporating the Standard Contractual Clauses with the Customer. and 5.2.4 provide to Customer for review such copies of the Contracted Processors' agreements with Subprocessors (which may be redacted to remove confidential commercial information not relevant solution in good faith to the requirements issue in question, then either Party may terminate this Agreement and we will provide a pro-rated refund for any prepaid but unused fees. You confirm that Section 4.2 constitutes general written authorization for the purposes of this Addendum) as Customer may request from time to time. 5.3 SentinelOne GDPR. We shall ensure that each Subprocessor performs its obligations under sections 2.1, 3, 4, 6.1, 7.2, 8 and 10.1, as they apply to Processing remain liable for any processing of Customer Personal Data carried out by subprocessors engaged under the Agreement. Upon your request, we will tell you where Customer Data is located. Notwithstanding anything to the contrary in this Section, if we and you have agreed that SubprocessorCustomer Data will be stored in any particular location, as if it were party to this Addendum we will store such Customer Data in place of SentinelOnethe agreed location.

Appears in 1 contract

Sources: Data Processing Agreement

Subprocessing. 5.1 Customer 6.1 Each Company Group Member authorises SentinelOne Vendor and each Vendor Affiliate to appoint (and permit each Subprocessor appointed in accordance with this section 5 6 to appoint) Subprocessors in accordance with this section 5 6 and any restrictions in the Principal Agreement. SentinelOne . 6.2 Vendor and each Vendor Affiliate may continue to use those Subprocessors already engaged by Vendor or any Vendor Affiliate as at the date of this Addendum, subject to Vendor and each Vendor Affiliate in each case as soon as practicable meeting the obligations set out in section 6.4. 6.3 Vendor shall make available to Customer the current list of Subprocessors that are processing Customer Personal Data, attached as Annex 3. SentinelOne shall provide Customer give Company prior written notice of the appointment of any new Subprocessor, including full details of the Processing to be undertaken by the Subprocessor. If, within thirty seven (307) days of receipt of that notice, Customer Company notifies SentinelOne Vendor in writing of any objections (on reasonable grounds) to the proposed appointment, and further provides commercially : Neither Vendor nor any Vendor Affiliate shall appoint (or disclose any Company Personal Data to) that proposed Subprocessor until reasonable justifications to such objections based on valid concerns regarding such proposed Subprocessor’s business practices relating to data protection, then (i) SentinelOne shall work with Customer in good faith steps have been taken to address Customer’s the objections regarding the new Subprocessor; raised by any Company Group Member and (ii) where Customer’s concerns cannot be resolved within thirty (30) days from SentinelOne's receipt of Customer's notice, notwithstanding anything in the Agreement, Customer may, by providing SentinelOne Company has been provided with a reasonable written notice to with immediate effect, terminate explanation of the Agreement and SentinelOne shall refund to Customer all prepaid Fees for the Solutions attributable to the Subscription Term (as outlined in the applicable Purchase Order) following the termination of these Termssteps taken. 5.2 6.4 With respect to each Subprocessor, SentinelOne Vendor or the relevant Vendor Affiliate shall: 5.2.1 before 6.4.1 Before the Subprocessor first Processes Customer Company Personal DataData (or, where relevant, in accordance with section 6.2), carry out adequate due diligence to ensure that the Subprocessor is capable of providing the level of protection for Customer Company Personal Data required by the Principal Agreement; 5.2.2 6.4.2 ensure that the arrangement between on the one hand (a) SentinelOneVendor, or (b) the relevant Vendor Affiliate, or (c) the relevant intermediate Subprocessor; and on the other hand, hand the Subprocessor, is governed by a written contract including terms which offer at least the same level of protection for Customer Company Personal Data as those set out in this Addendum and meet the requirements of Article article 28(3) of the GDPR; 5.2.3 6.4.3 if that arrangement involves a Restricted Transfer, ensure that the Standard Contractual Clauses are at all relevant times incorporated into the agreement between on the one hand hand (a) SentinelOneVendor, or (b) the relevant Vendor Affiliate, or (c) the relevant intermediate Subprocessor; and on the other hand the Subprocessor, or before the Subprocessor first Processes Customer Company Personal Data procure that it enters into an agreement incorporating the Standard Contractual Clauses with the Customer. relevant Company Group Member(s) (and Company shall procure that each Company Affiliate party to any such Standard Contractual Clauses co-operates with their population and execution); and 5.2.4 provide 6.4.4 Provide to Customer Company for review such copies of the Contracted Processors' agreements with Subprocessors (which may be redacted to remove confidential commercial information not relevant to the requirements of this Addendum) as Customer Company may request from time to time. 5.3 SentinelOne 6.5 Vendor and each Vendor Affiliate shall ensure that each Subprocessor performs its the obligations under sections 2.1, 33.1, 4, 6.15, 7.27.1, 8 8.2, 9 and 10.111.1, as they apply to Processing of Customer Company Personal Data carried out by that Subprocessor, as if it were party to this Addendum in place of SentinelOneVendor. 6.6 With respect to Restricted Transfers to a Subprocessor which is not a Vendor Affiliate: 6.6.1 The data exporter and each Subprocessor shall comply with the requirements set out in the UK Data Protection Laws, the EU Data Protection Laws, and, where applicable, the FADP. 6.6.2 If the Restricted Transfer is subject to UK Data Protection Laws, the UK Addendum shall be deemed to be incorporated into and form an integral part of this Addendum. The UK Information Commissioner's Office's Mandatory Clauses shall be deemed completed as follows: Table 1, Table 2 (including the relevant information from this Addendum), Table 3 (inserting “UK Data Protection Laws”), and Table 4 (neither party may terminate the UK Addendum under Section 19).

Appears in 1 contract

Sources: Data Processing Agreement

Subprocessing. 5.1 Customer 6.1 Where there is no subprocessing at the date of this agreement, these clauses cover GDPR requirements in the event that subprocessors are required at a future date. 6.2 The Client authorises SentinelOne ▇▇▇▇▇ to appoint (and permit each Subprocessor appointed in accordance with this section 5 paragraph 6 to appoint) Subprocessors in accordance with this section 5 paragraph 6 and any restrictions in the Agreement. SentinelOne agreement. 6.3 Where applicable, ▇▇▇▇▇ may continue to use those Subprocessors already engaged by ▇▇▇▇▇ as at the date of this Schedule, subject to Oleeo as soon as practicable meeting the obligations set out in paragraph 6.5. 6.4 Oleeo shall make available to Customer give the current list of Subprocessors that are processing Customer Personal Data, attached as Annex 3. SentinelOne shall provide Customer Client prior written notice of the appointment of any new Subprocessor, including full details of the Processing to be undertaken by the Subprocessor. If, within thirty (30) fourteen days of receipt of that notice, Customer the Client notifies SentinelOne ▇▇▇▇▇ in writing of any objections (on reasonable grounds) to the proposed appointment, and further provides commercially reasonable justifications to such objections based on valid concerns regarding such proposed Subprocessor’s business practices relating to data protection, then (i) SentinelOne : 6.4.1 ▇▇▇▇▇ shall work with Customer the Client in good faith to consider alternatives to any obligations; 6.4.2 Oleeo shall not appoint (or disclose any Client Personal Data to) that proposed Subprocessor until reasonable steps have been taken to address Customer’s the objections regarding raised by the new SubprocessorClient and the Client has been provided with a reasonable written explanation of the steps taken; and (ii) where Customer’s concerns and 6.4.3 Where an alternative solution cannot be resolved within thirty (30) days from SentinelOne's receipt of Customer's noticefound, notwithstanding anything in the Agreement, Customer may, by providing SentinelOne with a written notice to with immediate effect, terminate the Agreement and SentinelOne shall refund to Customer all prepaid Fees for the Solutions attributable to the Subscription Term (as outlined in contrary, the applicable Purchase Order) following the termination parties, acting reasonably, shall seek to agree a Subprocessor which is acceptable to both of these Termsthem. 5.2 6.5 With respect to each Subprocessor, SentinelOne Oleeo shall: 5.2.1 6.5.1 before the Subprocessor first Processes Customer Client Personal DataData (or, where relevant, in accordance with paragraph 6.3), carry out adequate due diligence to ensure that the Subprocessor is capable of providing the level of protection for Customer Client Personal Data required by the Agreementagreement; 5.2.2 6.5.2 ensure that the arrangement between on the one hand (a) SentinelOneOleeo, or (b) the relevant intermediate Subprocessor; and on the other hand, hand the Subprocessor, is governed by a written contract including terms which impose substantively the same obligations on the Subprocessor as this Schedule imposes on Oleeo, which offer at least the same level of protection for Customer Client Personal Data as those set out in this Addendum Schedule and meet the requirements of Article article 28(3) of the GDPR; 5.2.3 6.5.3 if that arrangement involves a Restricted Transfer, ensure that the Standard Contractual Clauses are at all relevant times incorporated into the agreement between on the one hand hand (a) SentinelOneOleeo, or (b) the relevant intermediate Subprocessor; and on the other hand hand, the SubprocessorSubprocessor or, or before the Subprocessor first Processes Customer Client Personal Data Data; (a) procure that it enters into an agreement incorporating the Standard Contractual Clauses with the Customer. Client; and 5.2.4 (b) ensure that any measures required to ensure that any Restricted Transfer of Customer Personal Data to the Subprocessor comply with the Data Protection Laws have been put in place before the Subprocessor is given access to the Client Personal Data; 6.5.4 provide to Customer the Client for review such copies of the Contracted Processors' agreements with Subprocessors (which may be redacted to remove confidential commercial information not relevant to the requirements of this AddendumSchedule) as Customer the Client may request from time to time. 5.3 SentinelOne 6.6 Oleeo shall ensure that each Subprocessor performs its the obligations under sections 2.1, 3paragraphs 3.2, 4, 6.15, 7.27.1, 8 8.2, 10 and 10.111.1, as they apply to Processing of Customer Client Personal Data carried out by that Subprocessor, as if it were party to this Addendum Schedule in place of SentinelOneOleeo. 6.7 Oleeo shall remain primarily liable for the acts and omissions of its Subprocessors.

Appears in 1 contract

Sources: Recruitment Application Service Agreement