<img alt="" src="https://secure.detailsinventivegroup.com/787475.png" style="display:none;">

Appendix I - DATA PROCESSING ADDENDUM

This DPA forms part of, and is incorporated by reference into, the Agreement between the parties. It governs the processing of Personal Data by Snapfix on the Customer's behalf in connection with the Services. This DPA supplements but does not replace the Agreement. In the event of any conflict between this DPA and the Agreement with respect to the processing of Personal Data, this DPA shall prevail.

 

By entering into the Agreement, the Customer is deemed to have accepted the terms of this DPA. This DPA is effective as of the effective date of the Agreement ("Effective Date").

 

This DPA applies to processing of Personal Data subject to EU GDPR, UK GDPR, or the Data Protection Act 2018. Processing subject to U.S. state privacy laws is governed by Appendix II (U.S. State Privacy Law Addendum), which supplements this DPA.

 

1. Definitions

In this DPA, the following capitalised terms have the meanings given below. All other capitalised terms have the meanings given in the Agreement.

 

Agreement

The Services Agreement, Work Order, or other commercial agreement between Snapfix and the Customer, together with all schedules and exhibits.

Controller

A natural or legal person which determines the purposes and means of the processing of Personal Data, as defined in Data Protection Law.

Customer Data

All data, including Personal Data, submitted by or on behalf of Customer to the Services.

Data Protection Law

EU GDPR, UK GDPR, and the Data Protection Act 2018, together with any associated regulations, guidance, and codes of practice issued by competent supervisory authorities, each as amended or replaced from time to time.

Data Subject

An identified or identifiable natural person whose Personal Data is processed under this DPA.

EU GDPR

Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data.

Permitted Jurisdictions

The European Economic Area, the United Kingdom, and any third country or territory in respect of which an adequacy decision is in force or in respect of which appropriate safeguards (within the meaning of Article 46 EU GDPR or equivalent UK GDPR provision) are implemented by Snapfix, including the United States where the relevant Sub-processor is certified under the EU-US Data Privacy Framework or bound by Standard Contractual Clauses.

Personal Data

Any information relating to an identified or identifiable natural person, as defined in Data Protection Law, that is submitted by Customer to the Services or otherwise processed by Snapfix on the Customer's behalf under the Agreement.

Personal Data Breach

A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data transmitted, stored, or otherwise processed, which Snapfix has reasonably determined, following initial investigation, has in fact occurred.

Processing / Process

Any operation or set of operations performed on Personal Data, whether or not by automated means, including collection, storage, use, disclosure, combination, erasure, or destruction.

Processor

A natural or legal person which processes Personal Data on behalf of a Controller.

SCCs

The standard data protection clauses for the transfer of personal data to processors established in third countries adopted by the European Commission pursuant to Article 46(2)(c) EU GDPR (as updated from time to time), and/or the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU SCCs issued by the ICO, as applicable.

Services

The Snapfix software-as-a-service platform and related services provided to the Customer under the Agreement.

Sub-processor

Any third-party Processor engaged by Snapfix to process Personal Data on the Customer's behalf in connection with the Services.

UK GDPR

The retained EU law version of the EU GDPR, as it forms part of domestic law in the United Kingdom by virtue of the European Union (Withdrawal) Act 2018, as amended by the Data Protection, Privacy and Electronic Communications (Amendments etc) (EU Exit) Regulations 2019.

 

2. Roles of the Parties

2.1 The Customer is the Controller of Personal Data submitted to or generated through its use of the Services. The Customer is responsible for ensuring that it has a valid lawful basis under Data Protection Law for the processing of Personal Data and for the accuracy and lawfulness of all Personal Data it provides to Snapfix.

 

2.2 Snapfix acts as a Processor in respect of Personal Data processed on the Customer's behalf in connection with the provision of the Services. Snapfix shall process such data only in accordance with the Customer's documented instructions as set out in this DPA and the Agreement, unless otherwise required by applicable law. For the avoidance of doubt, the terms of this DPA and the Agreement constitute the Customer's complete and final processing instructions unless the Customer provides further written instructions that are expressly agreed by Snapfix in writing.

 

2.3 Snapfix acts as an independent Controller in respect of Personal Data processed for its own operational purposes, including account administration, billing, security monitoring, fraud prevention, product improvement, and legal compliance. Such processing is governed by Snapfix's Privacy Policy (https://snapfix.com/privacy) and not by this DPA. For the avoidance of doubt, Snapfix may process fully anonymised data, which has been irreversibly anonymised such that no individual can reasonably be identified from it, whether by Snapfix or any other party as an independent Controller, for the purposes of product improvement and model training. For the avoidance of doubt, pseudonymised or de-identified data that retains any reasonable possibility of re-identification does not fall within this clause. Such processing does not constitute processing of Personal Data and is not subject to this DPA.

 

2.4 Nothing in this DPA restricts Snapfix from complying with applicable law, court order, or direction from a competent regulatory authority. Snapfix shall, to the extent permitted by law, promptly notify the Customer of any such requirement before complying.

 

3. Processing Details and Instructions

3.1 The subject matter, nature, purpose, duration of processing, types of Personal Data, and categories of Data Subjects are set out in Schedule 1 to this DPA.

 

3.2 Snapfix shall process Personal Data only to the extent necessary to provide the Services. The Customer acknowledges that the configuration and use of the Services by the Customer and its users constitutes the Customer's primary documented instructions to Snapfix.

 

3.3 Snapfix shall promptly notify the Customer if it considers that any instruction received from the Customer infringes Data Protection Law. Snapfix's notification shall not constitute legal advice and shall not impose any obligation on Snapfix beyond those set out in this DPA.

 

3.4 Snapfix shall not be required to verify the lawfulness of the Customer's instructions, and the Customer shall indemnify Snapfix against any losses, claims, or regulatory penalties arising from processing carried out in accordance with the Customer's instructions.

 

4. Technical and Organisational Security Measures

4.1 Snapfix shall implement and maintain appropriate technical and organisational measures ("TOMs") designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access, having regard to the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risks to the rights and freedoms of natural persons.

 

4.2 The TOMs implemented by Snapfix as at the Effective Date are described in Schedule 2 to this DPA. Snapfix may update, modify, or replace individual security measures from time to time provided that the overall level of security is not materially reduced. Snapfix is not required to seek the Customer's approval for such updates.

 

4.3 The Customer acknowledges that the TOMs described in Schedule 2 are appropriate having regard to the nature of the Services. The Customer is responsible for implementing its own appropriate security measures in connection with its use of the Services, including in respect of end-user access credentials and configurations.

 

4.4 Snapfix shall make a current summary of its TOMs available to the Customer upon written request, subject to reasonable confidentiality protections.

 

5. Sub-processors

5.1 The Customer hereby grants Snapfix general written authorisation (within the meaning of Article 28(2) EU GDPR) to engage Sub-processors for the performance of the Services. The Sub-processors approved as at the Effective Date are listed in Schedule 3.

 

5.2 Snapfix shall, before engaging any new Sub-processor or making material changes to an existing Sub-processor arrangement, provide the Customer with prior written notice by updating the Sub-processor list and notifying the Customer through the mechanisms agreed between the parties (which may include email notification or publication on Snapfix's designated web page, accessible to the Customer). The notice period shall be no less than ten (10) days.

 

5.3 The Customer may raise a documented written objection to a new Sub-processor within ten (10) days of receiving notice, on grounds that are specific, reasonable, and directly related to data protection. Mere commercial preference or inconvenience shall not constitute valid grounds. If the Customer raises a valid objection, the parties shall negotiate in good faith for a period of up to twenty (20) days. If no mutually acceptable resolution is reached, Snapfix may, at its sole discretion: (a) continue to engage the Sub-processor, in which case the Customer's sole remedy is to terminate the affected Services upon thirty (30) days' written notice, without penalty for early termination of that element of the Services only; or (b) elect not to use the Sub-processor in connection with the Customer's data. For the avoidance of doubt, the Customer's right of termination under this clause does not extend to the Agreement as a whole unless the affected Sub-processor is essential to the core provision of all Services.

 

5.4 Snapfix shall impose data protection obligations on each Sub-processor by written contract that are no less protective than those set out in this DPA with respect to Personal Data. Snapfix shall remain liable to the Customer for the acts and omissions of its Sub-processors to the same extent as if Snapfix had performed the relevant processing directly, subject always to the liability limitations in the Agreement.

 

5.5 The current Sub-processor list is maintained by Snapfix and made available to the Customer upon written request or through Snapfix's designated notification mechanism. Snapfix is not required to publish Sub-processor information publicly.

 

6. International Data Transfers

The transfer mechanisms in this clause 6 and in Schedule 4 apply only to the extent transfers of Personal Data are subject to EU GDPR or UK GDPR. They do not apply to Personal Data governed solely by U.S. law.

 

6.1 Snapfix may process, or permit the processing of, Customer Personal Data in any Permitted Jurisdiction (as defined in clause 1). Snapfix shall ensure that any transfer of Customer Personal Data outside the EEA or the UK is made subject to a transfer mechanism set out in Schedule 4, or to such other mechanism as provides a level of protection equivalent to that required under EU GDPR or UK GDPR (as applicable), in each case together with any supplementary measures required by applicable guidance.

 

6.2 Snapfix shall not transfer Customer Personal Data to any jurisdiction in a manner that would reduce the effective level of protection below that required by Data Protection Law. In determining the appropriate safeguard, Snapfix shall conduct a reasonable transfer impact assessment where required by applicable guidance.

 

6.3 The Customer acknowledges that certain Sub-processors engaged by Snapfix for the provision of AI-assisted features, analytics, and infrastructure services are located in the United States and other jurisdictions outside the EEA. The use of those Sub-processors is authorised under the general authorisation in clause 5.1, subject to the safeguards in this clause 6.

 

6.4 Where the parties need to execute SCCs, a UK IDTA, or other transfer instrument in connection with this DPA, they shall cooperate in good faith to do so. The applicable module, options, and annexes for any SCCs incorporated into this DPA are set out in Schedule 4.

 

6.5 For the avoidance of doubt, Snapfix is not required to restrict processing to EEA-based infrastructure unless such restriction is expressly required by applicable Data Protection Law or a binding decision of a competent supervisory authority. Snapfix currently hosts primary Customer Data storage on AWS infrastructure located within the EEA but reserves the right to use infrastructure in other Permitted Jurisdictions for processing activities including AI features, analytics, and support functions.

 

7. Artificial Intelligence and Automated Processing

7.1 The Services incorporate features powered by third-party large language model ("LLM") and artificial intelligence ("AI") providers, including providers listed in Schedule 3. Snapfix may use AI and machine learning capabilities to provide certain features of the Services, including but not limited to summarisation, translation, task analysis, and intelligent workflow automation.

 

7.2 Where Customer Data (including Personal Data) is processed by an LLM or AI provider as part of the Services, such providers are engaged as Sub-processors and are subject to the requirements of clause 5 of this DPA. Snapfix shall use commercially reasonable efforts to ensure that AI Sub-processors do not use Customer Data to train general-purpose AI models without the Customer's consent, and shall include appropriate contractual restrictions in its agreements with AI Sub-processors to that effect, to the extent such restrictions are available on commercially reasonable terms.

 

7.3 The Customer acknowledges that:

i. AI processing involves the transmission of data to third-party AI providers who process that data in accordance with their own terms and data processing agreements, copies of which Snapfix will make available upon reasonable request;

ii. Customer is responsible for reviewing and validating any AI-generated content before relying on it;

 

7.4 Where the Services involve any solely automated decision-making that produces legal or similarly significant effects on Data Subjects (within the meaning of Article 22 EU GDPR or equivalent UK GDPR provision), Snapfix shall notify the Customer, and the Customer shall be responsible for ensuring that any applicable safeguards required by Data Protection Law are implemented.

 

8. Data Subject Rights

8.1 Snapfix shall, upon becoming aware of a request from a Data Subject exercising rights under Data Protection Law, promptly (and in any event within ten (10) business days) notify the Customer of such request. Snapfix shall not respond directly to Data Subject rights requests except: (a) to acknowledge receipt and direct the Data Subject to the Customer; or (b) where required to do so by applicable law.

 

8.2 Snapfix shall provide the Customer with reasonable technical and organisational assistance to enable the Customer to fulfil Data Subject rights requests within applicable statutory timeframes. Such assistance shall be calibrated to the nature of the request and the data Snapfix holds, and shall not impose obligations on Snapfix beyond those that are technically feasible and proportionate to the Services.

 

8.3 Where the volume or frequency of assistance requested under clause 8.2 is disproportionate, Snapfix may charge the Customer a reasonable fee for such assistance, calculated on the basis of Snapfix's reasonable costs.

 

9. Personal Data Breaches

9.1 Snapfix shall notify Customer without undue delay, and in any event within seventy-two (72) hours of Snapfix becoming aware of a confirmed Personal Data Breach, providing such information as is reasonably available at the time of notification. Notification shall be provided to the Customer's designated contact and shall include, to the extent then known:

i. the nature of the Personal Data Breach and, where possible, the categories and approximate number of Data Subjects and Personal Data records affected;

ii. the likely consequences of the breach; and

iii. the measures taken or proposed to address the breach and mitigate its effects.

 

9.2 Where all required information is not available at the time of initial notification, Snapfix may provide the information in phases without undue further delay. Snapfix's notification of a Personal Data Breach does not constitute an admission of fault or liability.

 

9.3 Snapfix shall not be required to notify the Customer of security incidents that do not constitute a Personal Data Breach or that relate solely to Snapfix's own systems and do not affect Customer Data.

 

9.4 The Customer is solely responsible for determining whether it is required to notify any supervisory authority or Data Subjects in connection with a Personal Data Breach and for making any such notifications. Snapfix shall provide reasonable cooperation to the Customer in connection with such notifications upon written request.

 

10. Data Protection Impact Assessments

10.1 Where the Customer is required by Data Protection Law to conduct a Data Protection Impact Assessment ("DPIA") in connection with its use of the Services, Snapfix shall provide reasonable assistance by making available relevant information about its processing activities and security measures that are within Snapfix's reasonable control to disclose.

 

10.2 Snapfix's obligation under clause 10.1 is limited to providing factual information about Snapfix's own processing. Snapfix shall not be required to prepare, review, or sign off on the Customer's DPIA, and shall not be liable for the adequacy or completeness of any DPIA prepared by the Customer.

 

11. Audit Rights

11.1 Snapfix shall make available to the Customer, upon reasonable written request, information reasonably necessary to demonstrate Snapfix's compliance with its obligations under this DPA. Snapfix's primary means of demonstrating compliance shall be through the provision of:

i. current security certifications (e.g. ISO 27001, SOC 2 Type II, or equivalent);

ii. completed standard information security questionnaires; or

iii. written responses to reasonable information requests.

 

11.2 The Customer may request an on-site audit of Snapfix's data processing activities, subject to: (a) no less than thirty (30) days' prior written notice; (b) no more than once per calendar year (except where a confirmed Personal Data Breach has occurred); (c) audit costs being borne by the Customer; (d) execution of a confidentiality undertaking satisfactory to Snapfix; and (e) the audit being conducted in a manner that does not unreasonably disrupt Snapfix's operations or compromise the confidentiality of other customers' data. Where Snapfix has provided third-party audit documentation under clause 11.1 within the preceding twelve months, the Customer shall not be entitled to conduct a duplicative on-site inspection unless it has specific, documented grounds for doing so.

 

11.3 Any auditor appointed by the Customer must be independent, appropriately qualified, and not a direct competitor of Snapfix. Snapfix may refuse access to any auditor that does not meet these requirements.

 

12. Data Retention, Return, and Deletion

12.1 Snapfix shall retain Customer Data only for as long as necessary to provide the Services, subject to any longer retention period required by applicable law or agreed in the Agreement.

 

12.2 Upon expiry or termination of the Agreement, Snapfix shall make Customer Data available for export by the Customer for a period of ninety (90) days following termination. After that period, Snapfix may delete or destroy all Customer Data without further obligation, unless the Customer has made a written request for return or deletion within that period.

 

12.3 At the Customer's written request made within the ninety (90) day period in clause 12.2, Snapfix shall (at the Customer's election): (a) return Customer Data in a commonly used machine-readable format; or (b) irreversibly anonymise Customer Data such that it can no longer be attributed to an identified or identifiable natural person. Snapfix is not required to provide written confirmation in the absence of a specific written request.

 

12.4 Notwithstanding the above, Snapfix may retain Personal Data to the extent and for the duration required by applicable law, including for legal hold, regulatory compliance, or dispute resolution purposes, provided that such retained data is not processed for any other purpose.

 

13. Confidentiality

13.1 Snapfix shall ensure that personnel authorised to process Customer Data are subject to binding confidentiality obligations, whether by contract or statute, and are informed of the confidential nature of the Customer Data.

 

14. Prohibited Content and Special Category Data

14.1 The Services are not designed or intended to process special categories of Personal Data (as defined in Article 9 EU GDPR or equivalent UK GDPR provision), including data revealing racial or ethnic origin, political opinions, religious beliefs, health data, biometric data for unique identification purposes, or data concerning sexual orientation. The Customer shall not submit such data to the Services without prior written agreement with Snapfix and the implementation of additional agreed safeguards.

 

14.2 The intentional uploading of images or personal information relating to minors for the purpose of identifying or profiling them is prohibited.

 

14.3 To the extent images or photographs processed through the Services could theoretically contain biometric data, such images are not processed by Snapfix in a manner that would constitute biometric processing for the purpose of unique identification under Data Protection Law.

 

14.4 The Customer shall indemnify Snapfix against any losses, claims, regulatory penalties, or third-party actions arising from the Customer's submission of prohibited or special category data in breach of this clause 14.

 

15. Liability

15.1 Each party's liability under or in connection with this DPA (whether in contract, tort, statute, or otherwise) is subject to the limitations and exclusions of liability set out in the Agreement. Where no limitation of liability is specified in the Agreement, each party's total aggregate liability to the other under or in connection with this DPA shall not exceed the total fees paid or payable by the Customer to Snapfix in the twelve (12) months immediately preceding the event giving rise to the claim.

 

15.2 Snapfix's liability under this DPA is further limited as follows:

i. Snapfix shall not be liable for any breach of this DPA to the extent caused by the Customer's instructions, acts, or omissions, or by the Customer's failure to comply with Data Protection Law.

ii. Snapfix shall not be liable for processing carried out by Sub-processors where Snapfix has complied with its obligations under clause 5.4 in selecting and supervising the Sub-processor.

iii. Snapfix shall not be liable for any indirect, consequential, special, or punitive damages arising from any breach of this DPA, to the maximum extent permitted by applicable law.

 

15.3 Where both parties are found by a competent court or authority to be responsible for damage caused by a breach of Data Protection Law, liability shall be apportioned in accordance with their respective degrees of fault. Each party reserves the right to claim contribution from the other to the extent permitted by applicable law.

 

16. Governing Law and Supervisory Authority

16.1 This DPA is governed by and construed in accordance with the same governing law and jurisdiction as the Agreement (State of Delaware, United States), except that, to the extent required for the validity of EU or UK data-transfer mechanisms, any SCCs or UK IDTA executed under Schedule 4 are governed by the law they specify.

 

16.2 The lead supervisory authority for Snapfix's EU/EEA data processing is the Irish Data Protection Commission. For processing activities subject to UK GDPR, the relevant supervisory authority is the UK Information Commissioner's Office.

 

17. General

17.1 Snapfix may update this DPA by providing thirty (30) days' written notice to Customer where such updates are required to reflect changes in applicable law or regulation, or to make administrative corrections that do not reduce Customer's rights or increase Customer's obligations under this DPA. Any other amendment to this DPA, including any change that affects either party's data protection obligations, requires the mutual written agreement of both parties. Continued use of the Services following notice of a permitted unilateral update shall constitute acceptance of such update.

 

17.2 This DPA may not otherwise be amended except by a written instrument signed by authorised representatives of both parties.

 

17.3 If any provision of this DPA is held invalid or unenforceable, the remaining provisions shall continue in full force. The invalid or unenforceable provision shall be replaced by a valid provision that most closely reflects the parties' original intent.

 

17.4 This DPA shall survive the termination or expiry of the Agreement to the extent necessary to give effect to its terms regarding confidentiality, data deletion, and liability.

 

17.5 The parties may execute this DPA electronically and in counterparts, each of which shall constitute an original.

 

17.6 Data Protection Contact. Snapfix has designated a point of contact for data protection matters under this DPA. All notices, requests, and communications relating to this DPA should be directed to:

 

Designated Data Protection Contact:

Snapfix Limited

93 George's Street Upper

Dun Laoghaire, Dublin, Ireland

Email: legal@snapfix.com

 

Snapfix may update its designated contact details by providing written notice to the Customer in accordance with the notice provisions of the Agreement.


Appendix II - U.S. STATE PRIVACY LAW ADDENDUM

This U.S. State Privacy Law Addendum ("US Addendum") supplements the DPA and applies to the processing of Personal Information (as defined below) that is subject to U.S. state privacy laws, including the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA") and comparable laws in other U.S. states (together, "U.S. Privacy Laws"). In the event of a conflict between this US Addendum and the DPA with respect to Personal Information governed by U.S. Privacy Laws, this US Addendum prevails.

 

1. Definitions

Terms such as "Business," "Service Provider," "Personal Information," "Sell," "Share," "Process," and "Business Purpose" have the meanings given in the CCPA. "Personal Information" means Personal Data that is subject to U.S. Privacy Laws.

 

2. Roles

For Personal Information subject to U.S. Privacy Laws, Customer is the Business and Snapfix is the Service Provider. Snapfix processes Personal Information solely on Customer's behalf and for the Business Purposes set out in the Agreement, the DPA, and the applicable Work Order.

 

3. Service Provider Obligations

Snapfix shall:

(a) not Sell or Share Personal Information;

(b) not retain, use, or disclose Personal Information for any purpose other than the Business Purposes specified in the Agreement, or as otherwise permitted by U.S. Privacy Laws, including outside the direct business relationship between the parties;

(c) not combine Personal Information received from Customer with Personal Information received from or on behalf of any other party, or collected from Snapfix's own interaction with the consumer, except as permitted by U.S. Privacy Laws;

(d) comply with applicable obligations under U.S. Privacy Laws and provide the same level of privacy protection as required of a Business;

(e) notify Customer without undue delay if Snapfix determines it can no longer meet its obligations under U.S. Privacy Laws; and

(f) grant Customer the right, upon notice, to take reasonable and appropriate steps to stop and remediate unauthorized processing of Personal Information.

 

4. Consumer Rights Assistance

Snapfix shall provide reasonable assistance to enable Customer to respond to verifiable consumer requests to know, delete, correct, or opt out, taking into account the nature of Snapfix's processing and the information reasonably available to Snapfix. Snapfix shall not respond directly to a consumer request except to direct the consumer to Customer or as required by law.

 

5. Deletion and Return

Upon Customer's direction or on termination, Snapfix shall delete or return Personal Information in accordance with clause 12 of the DPA, except where retention is required or permitted by law.

 

6. Certification

Snapfix certifies that it understands and will comply with the restrictions set out in this US Addendum.

 

SCHEDULE 1

Details of Processing

Data Controller

The Customer, as identified in the Agreement.

Data Processor

Snapfix Limited.

Subject matter

The provision of the Snapfix SaaS platform and related services, including maintenance management, housekeeping, checklists, chat, AI-assisted features, and integrations with third-party systems (e.g. Opera, IMS, D3x).

Duration

For the term of the Agreement and, following termination, for the period set out in clause 12.2 of the DPA.

Nature of processing

Collection, storage, organisation, use, disclosure, erasure, and destruction of Personal Data, including by automated means, as necessary to deliver the Services.

Purpose of processing

Provision and operation of the Services; customer support and incident response; security monitoring and fraud prevention; billing and account management; AI-assisted features where enabled by the Customer; compliance with legal obligations.

Types of Personal Data

Name; job title and role; email address; telephone number; device identifiers and IP addresses; log and usage data; message and chat data; task, job, and maintenance records; photographs, images, and video submitted through the Services; voice notes (where applicable); and any other data submitted by the Customer or its users.

Categories of Data Subjects

The Customer's employees, contractors, agents, and authorised users of the Services. To the extent included by the Customer, the Customer's guests, clients, or other third parties whose data is submitted to the Services.

Special categories

None intended or authorised without prior written agreement. See clause 14 of the DPA.

Frequency

Continuous and ongoing throughout the term of the Agreement.

Retention

Duration of the Agreement plus ninety (90) days following termination, unless a longer period is required by law or agreed in writing.

 

SCHEDULE 2

Technical and Organizational Measures

The following measures are implemented by Snapfix as at the Effective Date. Snapfix may update these measures from time to time in accordance with clause 4.2 of the DPA.

 

Encryption

All Personal Data is encrypted in transit using TLS 1.2 or higher.

All Personal Data is encrypted at rest using AES-256 or equivalent.

Media files (photos, video, voice notes) are stored in encrypted, access-controlled environments.

 

Access Controls

Role-based access control (RBAC) with the principle of least privilege.

Multi-factor authentication (MFA) required for all administrative access.

All user sessions are authenticated using secure login and token-based methods.

Access rights are reviewed periodically and revoked promptly on personnel change.

 

Infrastructure and Hosting

Primary Customer Data is hosted on Amazon Web Services (AWS) infrastructure within the EEA.

AWS is ISO 27001 certified and implements strict physical security controls across its data centres.

Geographic redundancy and daily encrypted backups are in place.

Disaster recovery procedures support a target recovery time objective (RTO) of 24 hours.

 

Monitoring and Incident Response

Continuous security monitoring, logging, and alerting for suspicious or unauthorised activity.

All production system access and modifications are logged.

Regular vulnerability assessments and independent penetration testing.

A documented incident response plan is maintained covering detection, containment, notification, and remediation.

 

Secure Development

Software development follows a secure development lifecycle (SDLC) incorporating code review, automated testing, and controlled CI/CD deployment.

All updates are tested in staging environments before production release.

 

Personnel and Governance

All personnel with access to Personal Data are subject to binding confidentiality obligations.

Mandatory GDPR and data protection training on onboarding and annually thereafter.

Sub-processors are subject to equivalent data protection obligations and reviewed at least annually.

 

SCHEDULE 3

Approved Sub-processors

Sub-processors approved as of the Effective Date are listed below. This list is maintained by Snapfix and made available to the Customer. Changes will be notified in accordance with clause 5.2 of the DPA.

 

Sub-processor

Service / Purpose

Location

Transfer Mechanism

Amazon Web Services (AWS)

Cloud infrastructure and primary data storage

EEA (eu-west-1)

Primary EEA hosting – no transfer

Google Cloud Platform

Storage, hosting, and ancillary infrastructure

EEA / US

SCCs / Adequacy (as applicable)

OpenAI / Anthropic

AI-assisted features (summarisation, translation, task analysis)

US

SCCs / DPF (as applicable)

HubSpot

CRM, customer communication, and support

US

SCCs / DPF

Firebase / Equals / Looker / DataDog

Analytics and usage monitoring

US / EEA

SCCs / DPF (as applicable)

SendGrid / Mailgun / Mailchimp

Transactional email delivery

US

SCCs / DPF

Stripe / Chargebee

Payment processing and subscription management

US / EEA

SCCs / DPF (as applicable)

Jira / Atlassian

Internal issue tracking and development operations

US / EEA

SCCs / DPF (as applicable)

Xero

Invoicing and financial operations

NZ / EEA

Adequacy / SCCs

Twilio

Transactional messages

US / EEA

SCCs / DPF

Note: 'DPF' refers to the EU-US Data Privacy Framework. 'SCCs' refers to the Standard Contractual Clauses adopted by the European Commission (2021/914) and/or the UK IDTA or UK Addendum, as applicable. Transfer mechanisms are reviewed periodically and updated where required.

 

SCHEDULE 4

International Transfer Mechanisms

This Schedule applies only to the extent transfers of Personal Data are subject to EU GDPR or UK GDPR. It does not apply to Personal Data governed solely by U.S. law.

 

Part A – EU / EEA to UK

Snapfix relies on the adequacy decision adopted by the European Commission in respect of the United Kingdom (Decision 2021/1772, as maintained or replaced from time to time) for transfers of Personal Data from the EEA to the UK. If that adequacy decision is revoked or suspended, the parties shall promptly implement EU SCCs (Module Two: Controller to Processor) or such other approved mechanism as may be agreed in writing.

 

Part B – UK to Third Countries

For transfers of Personal Data subject to UK GDPR from the UK to third countries (including the US), Snapfix shall rely upon:

the UK International Data Transfer Agreement (IDTA) as issued by the ICO; or

the UK Addendum to the EU SCCs (as issued by the ICO); or

an adequacy regulation made by the UK Secretary of State; or

such other mechanism as is approved under UK data protection law.

 

Part C – EEA to Third Countries (including the United States)

For transfers of Customer Personal Data from the EEA to third countries (including US-based Sub-processors), Snapfix shall rely upon:

an adequacy decision of the European Commission, including the EU-US Data Privacy Framework (where the recipient is DPF-certified);

EU SCCs (Module Two: Controller to Processor, Commission Decision 2021/914), with Annex I completed as per Schedule 1 and Annex II completed as per Schedule 2; or

binding corporate rules approved by a competent supervisory authority.

 

The parties agree to cooperate in good faith to execute any additional documentation required to give effect to the transfer mechanisms described in this Schedule. In the event of any conflict between this Schedule and the executed transfer documentation, the executed documentation shall prevail.