DATA PROCESSING ADDENDUM

Liquid Web as Controller

This Data Processing Addendum (the “Addendum”) forms a part of the services agreement or other written or electronic agreement (the “Agreement”) executed by and between [company name] with an address of [company main address] (“Service Provider”) and [Liquid Web Entity] with an address of [Liquid Web address] (“Liquid Web”). Except as modified below, the Agreement remains in full force and effect.

HOW THIS ADDENDUM APPLIES

This Addendum consists of the main body of the Addendum and Exhibit A (Description of Data Transfers), Exhibit B (Security Measures), and Exhibit C (List of Subprocessors). This Addendum sets out the rights and obligations of the parties with regard to Personal Data Processed by Service Provider on behalf of Liquid Web in connection with the Processing operations outlined in the Agreement (the “Services”) as further specified in Exhibit A.

Service Provider enters into this Addendum on behalf of itself and as an agent for each of its applicable Affiliates. Liquid Web is signing the Addendum on behalf of itself and, to the extent required under applicable Data Laws, in the name and on behalf of its Affiliates, if and to the extent Service Provider Processes Personal Data for such Liquid Web Affiliates. For the purposes of this Addendum only, and except where indicated otherwise, the term “Liquid Web” shall include Liquid Web and Liquid Web Affiliates.

This Addendum will be effective and replace any previously applicable data processing and security terms as of the date Liquid Web accepts or otherwise agrees to this Addendum. This Addendum supplements the Agreement. This Addendum does not replace any comparable or additional rights relating to Processing of Personal Data contained in the Agreement (including any existing data processing addendum to the Agreement), nor does it replace any data processing agreement that supplements a services agreement where Service Provider provides other, unrelated services to Authorized Affiliates.


Table of Contents

  1. DATA PROCESSING TERMS
  2. 1. Definitions
  3. 2. Processing
  4. 3. Restrictions on Use of Personal Data
  5. 4. Internal Records
  6. 5. Relocation (Transfers)
  7. 6. Access
  8. 7. Disclosure
  9. 8. Subprocessors
  10. 9. Inquiries
  11. 10. Cooperation
  12. 11. Security Safeguards
  13. 12. Data Breach Notification
  14. 13. Return or Destruction of Personal Data
  15. 14. Further Agreements
  16. 15. Inability to Comply
  17. 16. Audit
  18. 17. Indemnification
  19. 18. Order of Precedence
  20. 19. Execution and Termination
  21. EXHIBIT A – Description of Processing Activities
  22. EXHIBIT B – Technical and Organizational Measures
  23. EXHIBIT C – List of Subprocessors

DATA PROCESSING TERMS

1. Definitions

a. “Affiliate” means any entity that directly or indirectly controls, is controlled by, or is under common control with the subject entity. “Control,” for purposes of this definition, means direct or indirect ownership or control of more than 50% of the voting interests of the subject entity.

b. “Controller” means an entity that alone or jointly with others determines the purposes and the means of the Processing of Personal Data. For the purposes of this Addendum, Liquid Web is the “Controller.”

c. “Data Subject” means a natural person whose Personal Data is Processed in the context of the Agreement.

d. “EU GDPR” means Regulation (EU) 2016/679 … as may be amended, superseded, or replaced.

e. “EU SCCs” means the agreement executed by and between Service Provider and Liquid Web pursuant to the European Commission’s decision (EU) 2021/915 4 June 2021 on Standard Contractual Clauses for the transfer of Personal Data to Processors established in Third Countries which do not ensure an adequate level of data protection or any set of clauses approved by the European Commission which amends, replaces, or supersedes the same.

f. “FADP” means the Federal Act on Data Protection … together with the August 31, 2022 Data Protection Ordinance.

g. “GDPR” means the EU GDPR, FADP, and UK GDPR.

h. “Law(s)” means any statute, regulation, ordinance, rule, order, decree, or governmental requirement enacted, promulgated, or imposed by any governmental authority at any level (e.g., municipal, county, province, state or national). Law(s) includes all Privacy Laws.

i. “Personal Data” means any information … that relates to an identified or identifiable natural person … All Personal Data is Liquid Web confidential information.

j. “Personal Data Breach” means a breach of security leading to the accidental or unlawful loss, destruction, alteration, unauthorized disclosure of, or access to Personal Data.

k. “Personnel” means any employees, agents, consultants, or contractors of Service Provider or Liquid Web or Liquid Web’s affiliates, respectively.

l. “Privacy Laws” means Laws relating to the security and protection of Personal Data … including, without limitation, the GDPR, the California Privacy Rights Act, and similar laws … and including any rules, regulations, directives, principles and policies of Liquid Web.

m. “Process” or “Processing” means, with respect to Personal Data, any operation or set of operations performed upon Personal Data or sets of Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.

n. “Processor” means an entity which Processes Personal Data on behalf of a Controller. For the purposes of this Addendum, Service Provider is the “Processor.”

o. “Standard Contractual Clauses” or “SCCs” means, as applicable, the EU SCCs and UK IDTA.

p. “Subprocessor” means the entity engaged by the Processor … to Process Personal Data on behalf of and under the instructions of the Controller.

q. “UK GDPR” means the United Kingdom’s adoption of the EU GDPR and the 2018 Data Protection of 2018.

r. “UK IDTA” means the agreement executed by and between Service Provider and Liquid Web pursuant to the UK Information Commissioner’s Office’s issuance that came into force on 21 March 2022 or any set of clauses approved by the UK Information Commissioner’s Office which amends, replaces, or supersedes the same.

↑ Back to top

2. Processing

In the context of the Agreement, Service Provider shall act as a Processor of Liquid Web and only Process Personal Data for the specific and limited purposes set forth in the Agreement or otherwise listed in Exhibit A to this Addendum, on behalf of and in accordance with the instructions of Liquid Web, unless required to do so by applicable Laws (with notice to Liquid Web unless prohibited).

Liquid Web has the sole and exclusive authority to determine the purposes and means of the Processing of Personal Data by Service Provider. Service Provider shall Process Personal Data only as necessary to perform its obligations under the Agreement and in compliance with: (a) the express terms and conditions of the Agreement; (b) Liquid Web’s then-current privacy and information security policies; and (c) all applicable Privacy Laws.

Service Provider hereby consents to Liquid Web providing a summary or a representative copy of the relevant privacy provisions of the Agreement, including this Addendum, to legal authorities, including the U.S. Department of Commerce and to EU Data Protection Authorities, upon their request.

↑ Back to top

3. Restrictions on Use of Personal Data

Service Provider will not, and will not permit others to: (i) sell or share any Personal Data (including as such terms are defined under applicable Privacy Laws) or otherwise retain, use, or disclose Personal Data for any purpose other than the specific business purpose set forth in the Agreement …; (ii) retain, use, or disclose Personal Data outside of the direct business relationship … unless expressly permitted; or (iii) combine or update Personal Data with personal information from other sources, except as permitted under the Addendum and applicable Laws.

↑ Back to top

4. Internal Records

Service Provider shall maintain records of all Processing of Personal Data conducted on behalf ofLiquid Web, with at the minimum the categories of information required under applicable Privacy Laws and provide them to Liquid Web upon request.

↑ Back to top

5. Relocation.

Service Provider shall not transfer or store Personal Data outside the country to which Liquid Web or its Personnel originally delivered it to Service Provider for Processing (or, if it was originally delivered to a location inside European Economic Area, Switzerland, or United Kingdom (collectively, “Europe”), outside of Europe) without Liquid Web’s prior written consent. With Liquid Web’s written consent, Service Provider may transfer such Personal Data to the countries identified in Exhibit A to this Addendum, provided that Service Provider shall ensure that a mechanism to achieve adequacy in respect of that Processing is in place such as: (a) the requirement for Service Provider and any Subprocessor to execute with Liquid Web or Service Provider, as the case may be, Standard Contractual Clauses; or (b) the existence of any other specifically approved safeguard for data transfers (as recognized under applicable Privacy Laws) and/or the applicable Public Authority finding of adequacy. Currently, the parties agree that the relevant provisions contained in the Standard Contractual Clauses are incorporated by reference and are an integral part of this Addendum, modified as follows:

a. Roles of the Parties. Liquid Web is the data exporter and Service Provider is the data importer.


b. EU SCCs. Module 2 (Controller to Processor) or Module 3 (Processor to Processor), as applicable, applies if Personal Data is subject to a third-country transfer, the option under clause 7 applies, the option under clause 11 does not apply, the competent supervisory authority for the purposes of clause 13 is the Autoriteit Persoonsgegevens (Dutch Data Protection Authority), the governing law for the purposes of clause 17 is the laws of the Netherlands, and the parties agree that the courts of the Netherlands shall have exclusive jurisdiction to resolve any dispute arising from the EU SCCs.


c. Swiss Addendum. With respect to the Personal Data of Swiss Data Subjects, the EU SCCs (as modified above) are further modified as follows:

  • i. References to specific sections of the EU GDPR shall be replaced with the equivalent section of the FADP as applicable;
  • ii. References to the EU, member state, or member state law shall be interpreted as references to “Switzerland” or “Swiss law” as the case may be, and the term “member state” shall not be interpreted in such a way as to exclude data subjects in Switzerland from the possibility of suing for their rights in their place of habitual residence (i.e., Switzerland); 
  • iii. References to the “competent supervisory authority” and “competent courts” will be replaced with the “the Swiss Federal Data Protection and Information Commissioner” and the “relevant courts in Switzerland;” and
  • iv. The governing law shall be the laws of Switzerland.

d. UK IDA. All UK laws and places for claims shall apply, neither party may end the UK IDTA when it changes, the importer may transfer on the transferred data to another organization or person in accordance with Section 16.1 of the Mandatory Clauses without restriction, the parties will review the security requirements when there is a change to the Transferred Data, Purpose, Importer Information, TRA or risk assessment, the categories of Transferred Data and Data Subjects and purpose for processing will update automatically if the information is updated in the Agreement.

e. Additional Information. Exhibits A, B and C to this Addendum shall be considered as Annex I, Annex II, and Annex III to the EU SCCs. Exhibit A shall be considered the information required for Tables 1 to 3 of Part One of the UK IDTA and Exhibit B shall be considered as Table 4 to the UK IDTA.

f. Execution. The parties’ signatures to this Addendum shall be considered as signatures to the Standard Contractual Clauses; provided that, if so required by the Laws of any jurisdiction, the parties shall execute or re-execute the Standard Contractual Clauses as separate documents setting out the proposed transfers of Personal Data in such manner as may be required.

↑ Back to top

6. Access

Service Provider shall limit access to Personal Data to its Personnel who have a need to know the Personal Dataand who have explicitly agreed in writing to comply with legally-enforceable privacy, confidentiality, and security obligations that are substantially similar to those required by the Agreement and to only Process Personal Data in accordance with Liquid Web’s instructions, unless required to do so by applicable Laws, in which case Service Provider shall inform Liquid Web of the legal requirement before Processing, unless the applicable Law prohibits Service Provider from doing so.

↑ Back to top

7. Disclosure

Service Provider and its Personnel shall hold all Personal Data in strict confidence. Service Provider shall not sell, disclose, or transfer Personal Data to any third party, including a subcontractor, for any reason without Liquid Web’s prior written consent, unless such disclosure or transfer is contemplated under this Personal Data Addendum or the Agreement, required under applicable Law, necessary to comply with a subpoena or other legal process or in cooperation with law enforcement agencies or other government authorities, in which case Service Provider shall, wherever not prohibited by Law, notify Liquid Web promptly in writing before any such disclosure or transfer and comply with all reasonable directions of Liquid Web with respect to such disclosure or transfer.

↑ Back to top

8. Subprocessors

a. Without limiting any other obligation under the Agreement and except as otherwise provided in Section 8(b) of this Addendum, Service Provider may not subcontract or use a Subprocessor in connection with any of Service Provider’s rights or obligations concerning Personal Data without Liquid Web’s prior written consent. Service Provider must obtain Liquid Web’s prior consent for each change in Subprocessor(s) or subsequent Subprocessor(s) before any such change. Where Service Provider uses a Subprocessor with respect to any of Service Provider’s rights or obligations concerning Personal Data, Service Provider shall enter into a written agreement with the Subprocessor, requiring it to provide at least the same level of privacy protection as is required by this Addendum and impose the same obligations on the Subprocessor as are imposed on the Service Provider under this Addendum.

b. Service Provider has appointed the Subprocessors listed in Exhibit C to this Addendum to Process Personal Data in connection with the Agreement, and Liquid Web consents to that appointment.

c. Before any subprocessing, Service Provider must perform adequate due diligence to ensure that the Subprocessor is capable of Processing Personal Data with at least the same level of protection for the Processing of Personal Data and that the same obligations are imposed on the Subprocessor as are imposed on the Service Provider under this Addendum and applicable Privacy Laws. Service Provider shall only retain Subprocessors that Service Provider reasonably expects to be suitable and capable of performing the delegated obligations in accordance with the Agreement. Service Provider shall provide Liquid Web with reasonable information requested by Liquid Web to enable Liquid Web to verify each Subprocessor’s compliance with its obligations with respect to Personal Data, including to conduct an audit as provided in Section 16 (Audit) of this Addendum. If a Subprocessor fails to fulfill any obligation under the written agreement referred under Section 8(a) or applicable Privacy Laws, Service Provider will remain fully liable to Liquid Web for the performance of the Subprocessor’s obligations.

↑ Back to top

9. Inquiries

Service Provider shall promptly inform Liquid Web without unreasonable delay of any communications, requests, or complaints received by Service Provider which relate to Personal Data Processed by Service Provider in connection with the Agreement or which may be in Service Provider’s possession, custody, or control in connection with the Agreement. This includes (a) any Data Subjects’ requests to exercise their rights of (i) access, (ii) rectification, (iii) erasure, (iv) data portability, (v) restriction of Processing, or (vi) objection to the Processing; (b) any request or complaint received from any individual, including Liquid Web’s customers or employees; (c) any question, complaint, investigation or other inquiry from any data protection authority; and (d) any request for disclosure of or information about the Personal Data that are Processed by Service Provider from any public authority of any jurisdiction. Service Provider shall provide to Liquid Web without unreasonable delay a copy of any such request and may respond to such requests only in accordance with Liquid Web’s prior written authorization and instructions. Service Provider shall cooperate with and assist Liquid Web to take action to address and respond to such communications, requests, and complaints.

↑ Back to top

10. Cooperation

Taking into account the nature of the Processing and the information available to Service Provider, Service Provider shall reasonably cooperate with Liquid Web to comply with Privacy Laws, this Addendum, and Liquid Web’s instructions, and to assist Liquid Web in fulfilling its own obligations under Privacy Laws, including complying with Data Subjects’ requests to exercise their rights, replying to complaints from Data Subjects, replying to investigations and inquiries from supervisory authorities, conducting data protection impact assessments and prior consultations with supervisory authorities.

↑ Back to top

11. Security Safeguards

a. Without limiting any other obligation under the Agreement, Service Provider shall, taking into account the nature of the Personal Data and the risks involved in the Processing, maintain reasonable and appropriate security measures, including technical and organizational safeguards, designed to (a) ensure the security and confidentiality of Personal Data; (b) protect Personal Data against any anticipated threats or hazards to the security and integrity of such information; and (c) protect Personal Data against any actual or suspected unauthorized Processing, loss, use, disclosure or acquisition of, or access to such information.

b. Service Provider shall exercise all necessary and appropriate supervision over its relevant Personnel to maintain appropriate privacy, confidentiality, and security of Personal Data.

c. Reasonable and appropriate technical and organizational measures include at the minimum the security measures set forth in the Agreement and as set forth in Exhibit B, attached hereto. In assessing the appropriate level of security, Service Provider must take into account the state of the art, the costs of implementation and the nature, scope, context and purposes of Processing as well as the risk of varying likelihood and severity for the rights and freedoms of Data Subjects and the risks that are presented by the Processing.

d. Service Provider shall notify Liquid Web of any technical, operational, organizational, or other change having a material impact on the security, confidentiality, or protection of Personal Data, at least 30 days before implementing any such change. Service Provider agrees to submit its information security program to the audit provided under Section 16 (Audit).

↑ Back to top

12. Data Breach Notification

a. Without limiting any other obligation under the Agreement, Service Provider shall immediately inform Liquid Web in writing after becoming aware of a Personal Data Breach. Taking into account the nature of Processing and the information available to Service Provider, Service Provider shall assist Liquid Web in complying with its obligations under Privacy Laws to notify Data Subjects of a Personal Data Breach. Service Provider must document all Personal Data Breaches, including all material facts known to Service Provider relating to the Personal Data Breach, its effects, and remedial actions taken by Service Provider. Service Provider must promptly take all necessary corrective actions (at its sole cost and expense), cooperate fully with Liquid Web in all reasonable and lawful efforts to respond to and mitigate the effects of Personal Data Breach, and reimburse Liquid Web for any costs it incurs in connection with the foregoing.

b. Except to the extent prohibited by applicable Law, Service Provider must obtain Liquid Web’s prior written approval before the publication or communication of any disclosures, filings, communications, notices, press releases, or reports related to any Personal Data Breach which mention Liquid Web or its affiliates or which would reveal any of Liquid Web’s confidential information, including any information about Service Provider’s relationship with Liquid Web or any of Liquid Web’s affiliates. Any violation or threatened violation of this clause, or the occurrence of any Personal Data Breach, will cause immediate and irreparable harm to Liquid Web for which money damages would not constitute an adequate remedy; therefore, in addition to any other available remedies, Liquid Web may seek injunctive or other equitable relief relating to any such violation or incident without proof of actual damages or the posting of bond or other security.

↑ Back to top

13. Return or Destruction of Personal Data

Promptly upon the expiration or termination of the Agreement, or upon request by Liquid Web at any other time, Service Provider shall return to Liquid Web or its designee, or at Liquid Web’s request, securely destroy every original and copy in every media of all Personal Data in Service Provider’s possession, custody, or control. If applicable Law or Service Provider’s data retention policy requires retention of the Personal Data, Service Provider will ensure the continued confidentiality of the Personal Data in accordance with applicable Privacy Laws, will not actively Process the Personal Data after the date when the return or destruction would have otherwise been required, will continue to comply with the obligations in the Agreement with respect to such Personal Data, and shall not use or disclose any Personal Data after expiration or termination of the Agreement.

↑ Back to top

14. Further Agreements

Service Provider shall enter into any further privacy, confidentiality, or information security agreement reasonably requested by Liquid Web necessary to comply with applicable Privacy Laws. In case of any conflict between the Agreement and any such further privacy, confidentiality, or information security agreement, such further agreement shall prevail with regard to the Processing of Personal Data covered by it.

↑ Back to top

15. Inability to Comply

Service Provider shall promptly notify Liquid Web in writing if Service Provider cannot comply with its obligations regarding Personal Data or under this Addendum. In particular, Service Provider shall notify Liquid Web if any failure of Service Provider or any Law or other requirement prevents Service Provider (a) from fulfilling its obligations under this Addendum or applicable Privacy Laws, or (b) from complying with Liquid Web’s instructions concerning Personal Data, unless such notice to Liquid Web is prohibited by Law. If this is the case, the Parties shall use their best efforts to remedy the situation. Notwithstanding the foregoing, Liquid Web may, without penalty of any kind and in addition to any other remedies under the Agreement, take any steps that Liquid Web deems necessary or advisable to stop or remediate any unauthorized Processing, which may include suspending the transfer or disclosure of Personal Data to Service Provider or access to Personal Data by Service Provider and terminating any further Processing of Personal Data by Service Provider. Suspension or termination of Service Provider’s Processing of Personal Data under this Section will not relieve Service Provider of any obligations under the Agreement and will not limit or modify any rights or remedies available to Liquid Web.

↑ Back to top

16. Audit

During the term of the Agreement and for 1 year thereafter:
a. Without limiting any other obligation under the Agreement, upon Liquid Web’s request, Service Provider shall make available to Liquid Web all information reasonably requested by Liquid Web to enable Liquid Web to verify Service Provider’s compliance with this Addendum.

b. Upon Liquid Web’s reasonable request, Service Provider shall allow Liquid Web (or an inspection body composed of independent members selected by Liquid Web, and which possess any professional qualifications required by Law) to audit and review Service Provider’s information security program, data processing facilities, and data protection compliance program to verify Service Provider’s compliance with this Addendum and applicable Privacy Laws. If the audit is performed by an inspection body, Liquid Web shall require the members to sign Liquid Web’s standard nondisclosure agreement.

c. The Parties shall reasonably cooperate concerning the timing and duration of the audit. Service Provider shall cooperate with such audit and implement all commercially reasonable changes to its information security program, data processing facilities, and data protection compliance program that, as a result of the audit, are required to ensure Service Provider’s compliance with this Addendum and applicable Privacy Laws.

d. If Service Provider fails to allow or cooperate with any audit or implement any required changes to the information security program, Liquid Web may suspend the Processing of Personal Data by Service Provider and may terminate the Agreement with no further liability to Service Provider if Liquid Web determines that doing so is required to comply with its obligations.

↑ Back to top

17. Indemnification

Service Provider shall, at its expense, defend, indemnify and hold harmless Liquid Web, its affiliates and their shareholders, directors, officers, employees, agents, successors and assigns, from and against any and all claims, liabilities, demands, suits, or causes of action and all damages, penalties, fines, costs, fees and expenses (including reasonable attorneys’ fees and disbursements) arising therefrom, that result or are claimed to result, in whole or in part from any Personal Data Breach or Service Provider’s failure to comply with any of its obligations under this Addendum.

↑ Back to top

18. Order of Precedence

This Addendum is incorporated into and forms part of the Agreement. For matters not addressed under this Addendum, the terms of the Agreement apply. In the event of a conflict between the terms of the Addendum and an Exhibit to this Addendum, the terms of the Exhibit shall prevail, and in the event of a conflict between the Exhibits, the Standard Contractual Clauses shall prevail. Nothing in the Agreement shall limit Service Provider’s indemnification obligations under this Addendum or Service Provider’s liability for a breach of its obligations under this Addendum. This Addendum and any dispute or claim arising out of or in connection with it or its subject matter or formation shall be governed by and construed in accordance with the laws applicable to the Agreement.

↑ Back to top

19. Execution and Termination

The parties represent and warrant to each other that each has the legal power and authority to enter into this Addendum. This Addendum cannot be modified, amended, or changed except in writing and signed by the parties to this Addendum. This Addendum may be executed in counterparts, each of which shall be deemed an original, but all of which together shall constitute one and the same instrument. The parties consent to the use of electronic signatures and electronic transmission of this Addendum. This Addendum is entered into as of the date of the last signature set forth below and will continue in effect until the expiration or termination of the Agreement, unless terminated as per the terms of this Addendum. Liquid Web will at all times have the right to terminate this Addendum on written notice to Service Provider. Termination or expiration of this Addendum shall not discharge Service Provider from its obligations that by their nature are meant to survive the termination or expiration of this Addendum. Notwithstanding anything to the contrary in the Agreement, the obligations pursuant to this Addendum shall survive termination of the Agreement.

↑ Back to top


EXHIBIT A – Description of Processing Activities

  1. Controller. The Liquid Web entity specified on Page 1 of the Addendum.
    Key contact details: Director of Security, [email protected]
  2. Processor. The Service Provider entity specified on Page 1 of the Addendum.
    Key contact details: [Job title and email address]
  3. Description of Services. _____
  4. Data Subjects. The personal data transferred concern the following categories of data subjects: _____
  5. Categories of Data. The personal data transferred concern the following categories of data: _____
  6. Special Categories of Data. The personal data transferred concern the following special categories of data: _____
  7. The frequency of the sharing of data and the transfer thereof (e.g., whether the data is transferred on a one-off or continuous basis):_____
  8. Processing operations. The personal data transferred will be subject to the following basic Processing activities : _____
  9. The period for which the personal data will be retained, or, if that is not possible, the criteria used to determine that period _____
  10. Countries where Processing will occur. _____

↑ Back to top

EXHIBIT B – Technical and Organizational Measures

Below sets forth a description of the technical and organizational measures implemented by Service Provider to ensure an appropriate level of security, taking into account the nature, scope, context and purposes of the Processing activities as well as well as the risks for the rights and freedoms of natural persons.

[Service Provider to provide/cross reference to TOMs within the Agreement]

↑ Back to top

EXHIBIT C – List of Subprocessors

Subprocessor NameSubprocessor Address and Contact InformationDescription of Processing
_______________

↑ Back to top


Liquid Web Data Processing Addendum (LW as Controller) – December 1, 2025 Version