This Data Protection Addendum (“DPA”) forms part of the Master Subscription Agreement between Aryaka and Customer (as applicable, the “Agreement”) under which Aryaka provides the Services to Customer. Capitalized terms used but not defined in this DPA shall have the meaning as set forth in the Agreement.

1. DEFINITIONS

1.1.Controller” means the entity which, alone or jointly with others, determines the purposes and means of Processing of Personal Data.

1.2.Data Protection Laws” mean all laws applicable to the respective Party’s Processing of Personal Data.

1.3.Data Subject” means any individual about whom Personal Data may be Processed under this DPA.

1.4.Personal Data” means information that relates to an identified or identifiable natural person that is provided by the Customer to the Services.

1.5.Process” or “Processing” means any operation or set of operations performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaption or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction of Personal Data.

1.6.Processor” means the entity which Processes Personal Data on behalf of the Data Controller.

2. RELATIONSHIP BETWEEN THE PARTIES. Customer and Aryaka have entered into an Agreement for Services. The Parties acknowledge that Customer is a Controller for purposes of the Agreement and Aryaka is a Processor. The Parties will Process Personal Data in accordance with the Agreement and applicable Data Protection Laws.

3. CUSTOMER OBLIGATIONS. Customer will provide only Personal Data that is adequate, relevant, and reasonably necessary for Aryaka to perform the Services. Customer represents and warrants that its collection of Personal Data and disclosure to Aryaka complies with all applicable Data Protection Laws.

4. INSTRUCTIONS. Aryaka will Process the Personal Data only (i) in accordance with the Customer’s instructions as documented in the Agreement and further described in Annex IB; and (ii) as needed to comply with applicable law, provided that Aryaka shall not be required to act on any Customer instruction that could (in the reasonable opinion of Aryaka) cause Aryaka to breach applicable law. Aryaka will inform Customer if it believes that any Customer instructions regarding Personal Data Processing would violate applicable Data Protection Law.

5. SECURITY. Aryaka will take reasonable steps to implement appropriate technical and organizational measures designed to protect Personal Data against anticipated threats or hazards to its security, confidentiality, or integrity. Aryaka will ensure that persons authorized to Process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

6. DATA BREACH. Aryaka will notify Customer without undue delay whenever Aryaka learns that there has been a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data Processed (each, a “Data Breach”), unless prohibited by applicable law or otherwise instructed by law enforcement or a supervisory authority. Taking into account the nature of Processing and the information available to Aryaka, Aryaka will take reasonable steps to assist the Customer at Customer’s reasonable request in complying with the Customer’s notification obligations regarding data breaches as required by applicable law. Aryaka reserves the right to charge a reasonable fee to Customer for any requested assistance.

7. RETURN OR DISPOSAL. Within 30 days of termination of the Agreement, Customer may request that Aryaka destroy or return all Personal Data to Customer, unless applicable law requires storage of the Personal Data by Aryaka.

8. AUDITS; INQUIRIES. Upon Customer’s reasonable request (to be exercised no more than once a year, unless required more frequently by a supervisory authority) Aryaka will promptly make available to Customer all information in its possession necessary to demonstrate Aryaka’s compliance with its obligations under this DPA and will allow for and contribute to reasonable audits. All information provided will be Aryaka’s Confidential Information and may not be disclosed without Aryaka’s prior written consent, except as required by applicable law.

9. SUBCONTRACTING. Customer authorizes Aryaka to transfer Personal Data to sub-processors for purposes of providing the Services to Customer. Aryaka will maintain a list of the sub-processors. A current list of sub-processors is included in Annex III. Aryaka will provide Customer 14 days’ prior notice when adding a sub-processor to this list and the opportunity to object to such addition. If Aryaka does not receive an objection within 14 days of the notice, the sub-processor is deemed to be accepted by Customer. Aryaka will enter into an agreement with such sub-processor that includes data protection terms similar to this DPA.

10. ARYAKA ASSISTANCE. At Customer’s reasonable request and taking into account the nature of the Processing, Aryaka will take reasonable steps to assist Customer with Customer’s obligation to respond to Data Subjects’ requests to exercise their rights under applicable law by taking appropriate technical and organizational measures. Taking into account the nature of the Processing and the information available to Aryaka, Aryaka also will assist Customer at Customer’s reasonable request in meeting its compliance obligations regarding carrying out data protection impact assessments and related consultations of supervisory authorities. Aryaka reserves the right to charge a reasonable fee to Customer for such requested assistance.

11. CALIFORNIA CONSUMER PRIVACY ACT (CCPA) PROVISIONS.

11.1. Legal Compliance. Aryaka will provide the same level of privacy protection for Personal Data of California residents as required of Customer under the CCPA. Aryaka will notify Customer in writing if Aryaka determines that it can no longer meet its obligations under the CCPA. Customer has the right, upon providing notice to Aryaka, to take reasonable and appropriate steps to stop and remediate unauthorized use of Personal Data, including where Aryaka has notified Customer that it can no longer meet its CCPA obligations.

11.2. Restriction on Processing. In no event may Aryaka: (a) disclose Personal Data of California residents to a third party for monetary or other valuable consideration or disclose Personal Data to a third party for cross-context behavioral advertising; (b) disclose Personal Data of California residents to any third party for the commercial benefit of Aryaka or any third party; (c) retain, use, or disclose Personal Data of California residents outside of Aryaka’s direct business relationship with Customer or for a commercial purpose other than the business purposes specified in the Agreement or as otherwise permitted by applicable laws; or (d) combine Personal Data of California residents with personal information that Aryaka receives from, or on behalf of, other persons, or collects from its own interaction with the Data Subject, except as permitted under applicable laws. Aryaka certifies that it understands and will comply with the foregoing restrictions.

12. DATA TRANSFERS.

12.1. Restricted Transfers of Personal Data Subject to GDPR. The EU Standard Contractual Clauses (Module 2 Controller to Processor) ((EU) 2021/914) (“EU SCCs”), as completed by Aryaka in accordance with the modular structure of the standard clauses and the elections set forth in this Section 12.1, are incorporated herein by reference. Together with the attached Annexes I and II, the EU SCCs will apply to any transfer of Personal Data that is subject to the EU General Data Protection Regulation ((EU) 2016/679) (“GDPR”). Notwithstanding the foregoing, the EU SCCs will not apply to the extent the transfer is covered by a decision adopted by a competent authority with jurisdiction over Customer declaring that a jurisdiction meets an adequate level of protection of Personal Data (an “Adequacy Decision”).

12.2. Restricted Transfers from Switzerland. The EU SCCs, as modified in this Section 12.2, will apply to any transfer of Personal Data that is subject to the Swiss Federal Act on Data Protection (FADP) and is not otherwise subject to an Adequacy Decision:

12.2.1. The term “EU Member State” must not be interpreted in such a way as to exclude data subjects in Switzerland from the possibility for suing their rights in their place of habitual residence (Switzerland) in accordance with Clause 18(c).

12.2.2. References in the EU SCCs to the GDPR are to be understood as references to the FADP.

12.2.3. In Clause 17, the EU SCCs will be governed by the laws of Switzerland.

12.2.4. In Annex I.C, the Swiss Federal Data Protection and Information Commissioner is the competent supervisory authority.

12.3. Restricted Transfers from the United Kingdom. Where the Transfer of Personal Data is subject to the laws of the United Kingdom (including the UK General Data Protection Regulation) and are not otherwise subject to an Adequacy Decision, the parties agree:

12.3.1. The provisions of the UK International Data Transfer Addendum to the EU Commission Standard Contractual Clauses, Version B1.0, in force from March 21, 2022 (“UK Addendum”), including Part 2 ‘Mandatory Clauses’, are herein incorporated by reference and shall apply in full;

12.3.2. In Table 1 of the UK Addendum, the names of the parties, their roles and their details shall be set out in the attached Annex 1;

12.3.3. In Tables 2 and 3 of the UK Addendum, Module 2 of the EU SCCs incorporated into this DPA by reference, including the information set out in the attached Annexes, shall apply; and

12.3.4. In Table 4 of the UK Addendum, either party may end the UK Addendum.

12.4. Processing and Transfers of Personal Data Subject to PIPL. To the extent that Aryaka Processes Personal Data of individuals located in mainland China in connection with the Services, such Processing is subject to the PIPL Supplement to Aryaka Data Protection Addendum (the “PIPL Supplement”), which supplements and forms part of this DPA. In the event of any conflict between this DPA and the PIPL Supplement with respect to Personal Data of individuals located in mainland China, the PIPL Supplement will prevail.

13. CONFLICTS; ENFORCEABILITY. If any provision of this DPA is held to be invalid or unenforceable by any court of competent jurisdiction, such holding will not invalidate or render unenforceable any other provision of this DPA or any other contract between Customer and Aryaka. This DPA supplements the Agreement. This DPA will control in the event of any inconsistency between the Agreement and this DPA. Any other provisions of or obligations under the Agreement that are otherwise unaffected by this DPA will remain in full force and effect. If this DPA, or any actions to be taken or contemplated to be taken in performance of this DPA, do not or would not satisfy either party’s obligations under the laws applicable to each party, the parties will negotiate in good faith upon an appropriate amendment to this DPA.

[Annex I follows]

ANNEX I

A. LIST OF PARTIES

Data exporter(s):

Name: See Order Form between Customer and Aryaka.
Address: See Order Form between Customer and Aryaka.
Contact person’s name, position and contact details: See Order Form between Customer and Aryaka.
Activities relevant to the data transferred under these Clauses: See Agreement between Customer and Aryaka.
Role (controller/processor): Controller

Data importer(s):

Name: Aryaka Networks, Inc.
Address: 4699 Old Ironsides Drive, Ste 470 Santa Clara, CA 95054
Contact person’s name, position and contact details: Kurtis Berger, Sr. Director, IT & Security, privacyofficer@aryaka.com
Activities relevant to the data transferred under these Clauses: See Agreement between Customer and Aryaka.
Role (controller/processor): Processor

B. DESCRIPTION OF TRANSFER

Categories of data subjects whose personal data is transferred:

  • Individuals encompassing the Customer’s staff, temporary workers, advisors, and all those affiliated with the Customer’s workforce or who utilize the system and services offered.
  • The Customer’s clients, suppliers, partners, vendors, and any third parties from whom the Customer may possess Personal Data.

Categories of personal data transferred:

  • Information pertaining to users of the Customer, including their contact details (name, email address, phone numbers of representatives), or any information voluntarily shared with Aryaka through the Services or alternative channels.
  • Metadata essential for delivering services tailored to the Customer’s specific environment. This metadata encompasses attributes such as file details, file type, hash values, command line arguments, network access data (comprising IP addresses and protocols), and network-related information (including internal network IP addresses, public IP addresses, and website URL data).

Sensitive data transferred (if applicable) and applied restrictions or safeguards that fully take into consideration the nature of the data and the risks involved, such as for instance strict purpose limitation, access restrictions (including access only for staff having followed specialized training), keeping a record of access to the data, restrictions for onward transfers or additional security measures:

None. Aryaka does not require or intentionally process sensitive personal data to provide the Services. If Customer elects to route network traffic containing sensitive data through the Secure Web Gateway or Firewall services, such data transits solely as a result of Customer’s configuration and is not accessed, stored, or used by Aryaka.

The frequency of the transfer: Continuous

Nature of the processing:

The processing consists of: (a) application of security functions to network traffic; (b) collection and processing of network metadata (such as IP addresses, protocols, URLs, and connection data) for service delivery, performance optimization, and technical support; and (c) temporary caching and logging as operationally necessary to provide the Services. Processing is automated; Aryaka does not access the content of Customer communications except as required to perform the contracted security functions.

Purpose(s) of the data transfer and further processing:

Provision of the Services to the Customer in accordance with the Agreement and the Order concluded between the parties.

The period for which the personal data will be retained, or, if that is not possible, the criteria used to determine that period:

Personal data will be retained for the period required to perform the Services under the Agreement unless a longer period is required by applicable law.

For transfers to (sub-) processors, also specify subject matter, nature and duration of the processing:

See description above.

[Annex II follows]

ANNEX II – SECURITY MEASURES

Aryaka maintains various policies, standards and processes designed to secure Personal Data. Following is a description of some of the core technical and organisational security measures implemented by Aryaka.

Physical Access Controls

Aryaka implements and maintains measures designed to prevent unauthorized persons from gaining physical access to Aryaka locations.

Technical Access Controls

Aryaka implements and maintains measures designed to prevent unauthorized persons from gaining access to Aryaka’s data processing systems, including:

  • Hybrid Distributed Denial-of-Service (DDoS) protection integrating detection and mitigation (on-premises or in the cloud) with cloud-based volumetric DDoS attack prevention, and 24×7 Emergency Response Team (ERT) support; and
  • Network edge security providing advanced perimeter security solutions that are built into Customer’s Software Defined – Wide Area Network (SD-WAN) appliance.

Data Access Controls

Aryaka implements and maintains measures designed to restrict access to its data processing system to individuals who need such access within the scope and to the extent covered by their respective access permission (authorization).

Job Controls

Aryaka implements and maintains measures designed to ensure that Personal Data being Processed in the performance of the Services for the Customer is Processed solely in accordance with the Agreement.

Availability Controls

Aryaka implements and maintains measures designed to protect Personal Data against disclosure, accidental or unauthorized destruction or loss.

[Annex III follows]

ANNEX III – LIST OF SUB-PROCESSORS

Salesforce:

Use: Customer Relationship Management

Location where instance is resident: United States

Accessed by Aryaka Personnel from: United States, India, Germany, United Kingdom, Canada, Australia, Japan, The Netherlands, South Korea, and Switzerland

NetSuite:

Use: Accounting

Location where instance is resident: United States

Accessed by Aryaka Personnel from: United States and India

Zuora:

Use: Billing

Location where instance is resident: United States

Accessed by Aryaka Personnel from: United States and India

Marketo:

Use: Marketing and Messaging

Location where instance is resident: United States

Accessed by Aryaka Personnel from: United States, United Kingdom, and India

[End of Agreement and Annexes I through III]