This Data Processing Addendum (the "DPA") is part of the Evaluation Agreement, or any other agreement that incorporates it (the "Agreement"), between Surface Security, Inc. ("Surface Security") and the customer that signed the Agreement ("Customer"). It applies whenever Surface Security processes Customer Personal Data on Customer's behalf. Terms defined in the Agreement, such as "Signature Record," "Affiliate," and "Threat Indicators," have the same meaning here.
1. Definitions
- "Customer Personal Data" means personal data in Customer Data (as defined in the Agreement) that Surface Security processes on Customer's behalf.
- "Data Protection Laws" means all laws that apply to the processing of Customer Personal Data under the Agreement. These include:
- the EU General Data Protection Regulation ("GDPR");
- the UK GDPR and Data Protection Act 2018;
- the Swiss Federal Act on Data Protection of 25 September 2020 ("FADP"); and
- U.S. state privacy laws such as the California Consumer Privacy Act ("CCPA").
- "SCCs" means the standard contractual clauses in the Annex to Commission Implementing Decision (EU) 2021/914 of 4 June 2021.
- "Security Incident" means a breach of security that leads to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Data.
- "Subprocessor" means a third party that Surface Security engages to process Customer Personal Data.
"Controller," "processor," "data subject," "personal data," "processing," "business," "service provider," "sell," and "share" have the meanings given in the applicable Data Protection Laws.
2. Roles and Instructions
2.1 Roles. For Customer Personal Data:
- Customer is a controller, or a processor acting for its Affiliates or other controllers.
- Surface Security is Customer's processor (or sub-processor) and CCPA service provider.
Customer enters into this DPA for itself and on behalf of its Affiliates that are controllers of Customer Personal Data. Those Affiliates exercise their rights through Customer. Surface Security is an independent controller of the Signature Record, and of business contact information of Customer's personnel that it uses to manage the relationship, as described in its Privacy Policy.
2.2 Instructions. Surface Security will process Customer Personal Data, including any transfer to a third country, only on Customer's documented instructions. The only exception is where Union or Member State law to which Surface Security is subject (or, for data not subject to the GDPR, other applicable law) requires otherwise. In that case, Surface Security will inform Customer of the requirement before processing, unless that law prohibits this on important grounds of public interest. Customer's instructions are set out in:
- the Agreement (including Section 4.4) and this DPA;
- Customer's configuration of the Enterprise Platform; and
- other written instructions consistent with the Agreement.
Surface Security will immediately inform Customer if, in its opinion, an instruction infringes Data Protection Laws.
2.3 Details. Annex 1 describes the processing.
2.4 Customer's obligations. Customer is responsible for having a lawful basis for the processing, and for giving the notices and obtaining the consents that Data Protection Laws require.
3. Surface Security's Obligations
3.1 Confidentiality. Surface Security will ensure that anyone it authorizes to process Customer Personal Data is bound by confidentiality obligations. Where Customer is subject to professional secrecy obligations, including section 203 of the German Criminal Code, Surface Security will keep secret any information protected by those obligations that it learns. It will require its personnel and Subprocessors, in writing, to do the same, and it acknowledges that unauthorized disclosure may be a criminal offense.
3.2 Security. Surface Security will implement the technical and organizational measures described in Annex 2. It may update these measures, but it will not materially reduce the overall protection they provide.
3.3 Security Incidents. Surface Security will notify Customer without undue delay, and in any event within 48 hours, after becoming aware of a Security Incident. It will send the notice to the signer and to any security-incident contact Customer designates. The notice will describe, as then known:
- the nature of the incident;
- the categories and approximate number of data subjects and records concerned;
- the likely consequences;
- the measures taken or proposed; and
- a contact point.
Surface Security will update the notice as more information becomes available. It will take reasonable steps to contain and investigate the incident and to limit its effects. It will not notify regulators or data subjects about the incident without Customer's consent unless the law requires it.
3.4 Assistance. Taking into account the nature of the processing, Surface Security will provide reasonable assistance to Customer with:
- data subject requests; and
- Customer's obligations under Articles 32 to 36 of the GDPR and equivalent laws, including data protection and risk assessments under U.S. state privacy laws.
Surface Security will promptly forward any data subject request it receives to Customer. It will not respond to the request, other than to refer the requester to Customer, unless Customer authorizes it.
3.5 Deletion and return. Surface Security will delete and return Customer Personal Data as described in Section 4.7 of the Agreement. The exception for data the law requires Surface Security to keep applies only where Union or Member State law (or, for data not subject to the GDPR, other applicable law) requires it. Surface Security will certify deletion in writing on request.
3.6 Audits. Surface Security will make available the information reasonably necessary to demonstrate its compliance with this DPA. This includes answers to security questionnaires and any third-party audit reports or certifications it holds.
Customer, or an independent auditor it appoints, may audit Surface Security's compliance, including by inspecting facilities Surface Security controls, in any of these cases:
- Customer reasonably determines that this information is not enough;
- there are indications of non-compliance;
- a Security Incident has occurred; or
- a supervisory authority or Customer's financial regulator requires it.
The auditor must be bound by confidentiality and must not be a Surface Security competitor. Routine audits are limited to once a year, with 30 days' written notice. The notice period is shorter where a regulator requires it or after a Security Incident. Audits must take place during normal business hours and must not disrupt Surface Security's operations. Customer bears its own costs of any audit. Surface Security will permit audits by Customer's regulators as the law requires. For U.S. state law purposes, Surface Security may instead arrange an annual independent assessment against an accepted framework, at its expense, and provide the report.
3.7 Government access. If Surface Security receives a legally binding request from a public authority for Customer Personal Data, it will, unless legally prohibited:
- promptly notify Customer and try to redirect the authority to Customer;
- challenge the request where there are reasonable grounds to consider it unlawful;
- disclose only the minimum the request requires; and
- on request, report the number of such requests it has received.
4. CCPA
To the extent the CCPA applies:
- Business purposes. Customer discloses Customer Personal Data to Surface Security only for these limited and specified business purposes, and Surface Security will process it only for them:
- providing the Enterprise Platform's browser security functions, meaning detecting and blocking threats and showing detections and forensics to Customer;
- onboarding and supporting Customer;
- the security and integrity of the Enterprise Platform; and
- deriving Threat Indicators under Section 4.4 of the Agreement.
- Restrictions. Surface Security will not:
- sell or share Customer Personal Data;
- retain, use, or disclose it for any other purpose, including any other commercial purpose, except as the CCPA permits;
- retain, use, or disclose it outside the direct business relationship between the parties; or
- combine it with personal information from other sources, except as the CCPA regulations permit.
- Compliance. Surface Security will comply with the CCPA obligations that apply to service providers and provide the same level of privacy protection the CCPA requires. It will cooperate with consumer requests and maintain reasonable security under California Civil Code section 1798.81.5.
- Oversight. Customer may take reasonable and appropriate steps to ensure Surface Security's compliance, including assessments under Section 3.6 at least once every 12 months. On notice, Customer may stop and remediate any unauthorized use of Customer Personal Data.
- Notice. Surface Security will notify Customer within five business days if it determines that it can no longer meet these obligations.
- Consumer requests. Customer will inform Surface Security of any consumer request it must help Customer comply with, and give it the information needed to comply.
- Subprocessors. Surface Security will notify Customer before engaging a Subprocessor, and bind each Subprocessor to these terms in writing.
- Assessments. Surface Security will reasonably cooperate with Customer's CCPA risk assessments and cybersecurity audits.
- De-identified data. For de-identified information derived from Customer Personal Data, Surface Security will:
- take reasonable measures to prevent it from being linked back to anyone;
- not attempt to re-identify it; and
- contractually require recipients to do the same.
5. Subprocessors
5.1 Authorization. Customer authorizes Surface Security to engage the Subprocessors listed in Annex 3. Surface Security will enter into a written agreement with each Subprocessor that imposes the same data protection obligations as this DPA, in particular sufficient guarantees of appropriate technical and organizational measures. On request, Surface Security will provide a copy, with commercial terms redacted. Surface Security remains fully liable for its Subprocessors.
5.2 Changes. Surface Security will notify Customer by email, to the signer and any privacy contact Customer designates, at least 30 days before engaging a new Subprocessor. Customer may object on reasonable data protection grounds within that period. If the parties cannot resolve the objection, Customer may end the Agreement.
6. Locations and International Transfers
6.1 Locations. Surface Security stores Customer Personal Data only in the United States, unless the parties agree otherwise in writing, and accesses it only from the United States. It will not change these locations, or add a Subprocessor that processes Customer Personal Data elsewhere, without notice under Section 5.2.
6.2 EEA. The SCCs apply to transfers of Customer Personal Data subject to the GDPR to a country not covered by an adequacy decision under Article 45 of the GDPR. For the United States, this means a recipient that is not certified under the EU-U.S. Data Privacy Framework for that data. For these transfers, Module 2 (controller to processor) of the SCCs is incorporated into this DPA. Where Customer is itself a processor, Module 3 (processor to processor) applies instead. For the SCCs:
- Customer is the data exporter and Surface Security is the data importer;
- the optional docking clause (Clause 7) applies, and Customer's Affiliates may accede by notice to Surface Security;
- under Clause 9, Option 2 (general written authorization) applies, with the notice period in Section 5.2;
- the optional language in Clause 11 does not apply;
- for Clause 13 and Annex I.C, the competent supervisory authority is:
- if Customer is established in an EU Member State, the supervisory authority responsible for Customer;
- if Customer is not established in the EU but has an Article 27 representative, the authority of the Member State where the representative is established; and
- otherwise, the authority of the Member State where the relevant data subjects are located, as Customer notifies Surface Security;
- for Clause 17, Option 1 applies, and the SCCs are governed by the law of the EU Member State where Customer is established or, if none, Ireland;
- for Clause 18(b), the courts of that Member State have jurisdiction;
- Annexes 1, 2, and 3 of this DPA complete Annexes I, II, and III of the SCCs; and
- by executing the Agreement, each party is deemed to have signed the SCCs, including Annex I, on the date of the Signature Record.
6.3 United Kingdom. For transfers from the United Kingdom, the SCCs apply as amended by the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses (version B1.0), issued by the Information Commissioner under section 119A of the Data Protection Act 2018, as revised. This includes its Part 2 Mandatory Clauses. The Addendum's tables are completed as follows:
- Table 1: with the parties' details in the Signature Record and Annex 1;
- Table 2: with the SCC version, modules, and options in Section 6.2;
- Table 3: with Annexes 1 to 3; and
- Table 4: either the importer or the exporter may end the Addendum.
Any successor UK transfer mechanism applies instead when it replaces the Addendum.
6.4 Switzerland. For transfers subject to the FADP, the SCCs apply with these changes:
- references to the GDPR are read as references to the FADP;
- the Swiss Federal Data Protection and Information Commissioner is the competent authority for transfers governed by the FADP, and the Section 6.2 authority is competent for transfers governed by the GDPR; and
- the term "member state" does not exclude data subjects in Switzerland from bringing claims in their place of habitual residence.
6.5 Other jurisdictions. Where Data Protection Laws require specific transfer terms, the parties will execute them on request.
6.6 Priority. If this DPA conflicts with the SCCs, the SCCs control.
7. General
This DPA is subject to the limitations of liability in the Agreement. However, nothing in the Agreement or this DPA limits either party's liability to data subjects under the SCCs or Data Protection Laws, or any liability that the SCCs provide may not be limited. If this DPA conflicts with the Agreement regarding personal data, the provision that better protects that data controls. Where the GDPR applies to Customer, this DPA (other than the SCCs, which Clause 17 governs) is governed by the law of the EU Member State where Customer is established or, if none, Ireland. This DPA ends when Surface Security no longer processes Customer Personal Data.
Annex 1: Description of Processing
A. Parties
- Data exporter: Customer, as identified in the Signature Record. Its contact person is the signer named in the Signature Record, or any privacy contact Customer designates. Its role is controller, or processor where Module 3 applies. Its activities relevant to the transfer are evaluating the Enterprise Platform.
- Data importer: Surface Security, Inc., 131 Continental Dr Suite 305, Newark, DE 19713, US. Its contact is its privacy team at legal@surface-security.com. Its role is processor, or sub-processor where Module 3 applies. Its activities are providing the Enterprise Platform, including Hosted Trials, onboarding, and support.
- Each party signs this Annex by executing the Agreement, on the date of the Signature Record.
B. Description of transfer
- Data subjects:
- employees, contractors, and other Authorized Users of Customer and its Affiliates whose browsers are connected to the Enterprise Platform;
- Customer's personnel who administer it; and
- individuals whose personal data appears in web pages, documents, or messages that Authorized Users view, such as Customer's customers, patients, and correspondents.
- Categories of personal data:
- user and device identifiers, such as names, email addresses, usernames, device names, and IP addresses;
- browsing activity, such as web addresses visited, timestamps, and page titles;
- page content and screenshots that the Enterprise Platform captures under Customer's configuration;
- security detections, alerts, and session forensics;
- authentication events and login metadata; and
- administrator account and audit log data.
- Sensitive data: Page content and screenshots may include special categories of data, including health data, and financial account data, depending on the sites Authorized Users visit. Safeguards:
- Customer's choice of which users and devices to connect, and its configuration of the Enterprise Platform (see Section 4.6 of the Agreement);
- encryption at rest;
- access limited to named personnel who need it to provide the service, using multi-factor authentication, with access logged;
- no model training (Section 4.5 of the Agreement); and
- deletion under Section 4.7 of the Agreement.
- Frequency: Continuous, for the duration of the Agreement.
- Nature and purpose:
- hosting, storing, analyzing, and displaying data to provide the Enterprise Platform's browser security features to Customer;
- for support, accessing Customer's environment or data as Customer authorizes; and
- deriving Threat Indicators under Section 4.4 of the Agreement.
- Duration and retention: For the term of the Agreement, then deleted as described in Section 3.5.
- Subprocessor transfers: As listed in Annex 3, for the same nature, purpose, and duration.
C. Competent supervisory authority
As determined under Section 6.2.
Annex 2: Technical and Organizational Measures
- Encryption: Data is encrypted in transit with TLS 1.2 or higher. Data in Hosted Trials is encrypted at rest with AES-256.
- Access control: Access to Customer Personal Data is limited to named personnel who need it to provide the service. Access uses individual accounts with multi-factor authentication, is logged, and is reviewed regularly. Access is removed promptly when personnel no longer need it.
- Separation: Each Hosted Trial is logically separated from other customers' data.
- Availability and resilience: Hosted Trials run on a major cloud provider's infrastructure, with backups that are encrypted and protected under this DPA.
- Secure development: Code review, dependency and vulnerability scanning, and cryptographically signed software releases.
- Vulnerability management: Timely patching of systems, prioritized by severity, and a published process for receiving vulnerability reports.
- Logging and monitoring: Security-relevant events in the systems that process Customer Personal Data are logged and monitored.
- Incident response: A documented process for detecting, investigating, and notifying Security Incidents.
- Data subject rights: The ability to find, export, and delete a specific user's data in a Hosted Trial on Customer's request.
- Personnel: Confidentiality obligations and security training for personnel with access to Customer Personal Data.
- Deletion: Customer Personal Data is deleted as described in Section 3.5.
- Testing and review: Surface Security reviews these measures at least once a year and updates them as needed.
- Subprocessors: Due diligence on Subprocessors' security, and written data protection terms with each of them.
- Physical security: Provided by Surface Security's cloud infrastructure Subprocessor, whose data centers hold independent security certifications.
Annex 3: Subprocessors
| Subprocessor | Service | Purpose | Location |
|---|---|---|---|
| Microsoft Corporation | Microsoft Azure | Cloud infrastructure for Hosted Trials | United States |
| Microsoft Corporation | Microsoft 365 (email, files, and meetings) | Support communications, files, and onboarding sessions | United States |
| Twilio Inc. | SendGrid | Delivery of service emails | United States |
| Microsoft Corporation | Microsoft Clarity | Usage analytics for the Hosted Trial console, only with each user's consent. On-screen content is masked, so only clicks and navigation are recorded | United States |