data processing addendum

Data Processing Addendum

This Data Processing Addendum (this “Addendum”) forms part of the Master Services Agreement, Terms of Service, End User Agreement, or other written or electronic agreement by and between Synack, Inc., a Delaware corporation (“Synack”) and the counterparty thereof (“Customer”) (the “Agreement”). This Addendum, together with all addendums, annexes, amendments, and attachments hereto, reflects the Parties’ agreement with regard to Synack’s Processing of Customer Personal Data in connection with providing Synack Services described in the Agreement. In the event of a conflict, the terms and conditions of this Addendum will prevail.

WHEREAS, Synack may process Customer Personal Data (as defined below) on behalf of Customer in connection with the Synack Services provided under the Agreement, and

WHEREAS, Synack and Customer seek to implement a data processing agreement that defines each party’s rights and obligations with respect to the processing of Customer Personal Data in compliance with the Privacy and Security Laws (as defined below).

NOW, THEREFORE, in consideration of the mutual covenants and agreements in this Addendum and the Agreement, and for other good and valuable consideration, the sufficiency of which is hereby acknowledged, Customer and Synack agree as follows:

1. DEFINITIONS.

The following terms, including any derivatives thereof, will have the meanings set forth below:

1.1 “Customer Personal Data” means any Personal Data that is Processed by Synack or its subcontractors on behalf of Customer as part of Customer’s use of the Synack Services.

1.2 “Data Subject” means an individual who is the subject of Personal Data.

1.3 “Personal Data” means information Synack processes for Customer that (a) identifies or relates to an individual who can be identified directly or indirectly from that data alone or in combination with other information in Synack’s possession or control or that Synack is likely to have access to, or (b) the relevant Privacy and Security Laws otherwise define as protected personal information.

1.4 “Privacy and Security Laws” means all applicable federal, state, and foreign laws and regulations relating to the processing, protection, or privacy of the Personal Data under the Agreement...

2. PROCESSING OF CUSTOMER PERSONAL DATA.

2.1 Synack will only Process Customer Personal Data for purposes of providing the Synack Services...

2.2 Synack will reasonably assist Customer with meeting Customer’s compliance obligations...

2.3 Upon instruction from Customer and upon termination of the Agreement...

2.4 Synack will not sell or disclose Customer Personal Data to any third parties...

...

3. SUBPROCESSORS.

3.1 Customer agrees that Synack may engage Sub-processors to process Customer Personal Data on Customer’s behalf...

3.2 Synack shall: (a) enter into a written agreement with each Sub-processor containing data protection obligations...

4. AUDIT.

4.1 Synack shall make available to Customer upon Customer’s written request information necessary to demonstrate compliance...

4.2 Synack shall permit, when Customer has reasonable cause to believe Synack is in non-compliance...

5. SECURITY MEASURES.

5.1 Synack shall adhere to the technical and organizational measures in the Information Security Addendum...

5.2 In the event Synack discovers or becomes aware of a Security Incident relating to Customer Personal Data...

6. DATA TRANSFERS.

6.1 Synack shall not transfer or authorize the transfer of Customer Personal Data from a country within the European Economic Area...

6.2 Synack and Customer each agree that, for Customer Personal Data transferred from Customer to Synack...

7. WARRANTY AND REMEDIES.

7.1 Synack will at all times comply with the Privacy and Security Laws...

7.2 Customer will at all times comply with the Privacy and Security Laws...

8. MISCELLANEOUS.

8.1 This Addendum will be effective from the last date set forth below...

8.2 All notices sent pursuant to this Addendum shall comply with the notice section set forth in the Agreement...

ATTACHMENT 1 TO DATA PROCESSING ADDENDUM: STANDARD CONTRACTUAL CLAUSES

...

ANNEX I

A. LIST OF PARTIES

Company Name See the contact information set forth in the Agreement or Work Order.
Company Address See the contact information set forth in the Agreement or Work Order.
Contact Person Name See the contact information set forth in the Agreement or Work Order.
Contact Person Position See the contact information set forth in the Agreement or Work Order.
Contact Person Address See the contact information set forth in the Agreement or Work Order.
Activities relevant to the data transferred Receipt of cybersecurity vulnerability testing services
Role (controller / processor) Controller

B. DESCRIPTION OF TRANSFER

Categories of data subjects whose personal data is transferred:

C. COMPETENT SUPERVISORY AUTHORITY

Identify the competent supervisory authority/ies in accordance with Clause 13: Republic of Ireland

APPENDIX ANNEX II

TECHNICAL AND ORGANISATIONAL MEASURES INCLUDING TECHNICAL AND ORGANISATIONAL MEASURES TO ENSURE THE SECURITY OF THE DATA

Description of the technical and organizational security measures implemented by the Data Importer can be found in the Information Security Addendum.

ANNEX III

LIST OF SUB-PROCESSORS

The controller has authorised the use of the following sub-processors:

Subprocessor Name Description of Processing Category Corporate Location
Amazon Web Services, Inc. Data hosting provider Commercial Synack Services Only USA
Anthropic, PBC – Claude Generative AI Operational Processes and Support USA
...

Synack Third-Party Subprocessors may be updated from time to time.