ֿData Processing Addendum

Updated November 2024

This Data Processing Addendum (“DPA”) applies as between Explorium, Inc. (“Explorium”) and the entity
engaging with Explorium as a customer (“Customer”), under the Order Form and Terms and Conditions
available here
(the “Agreement”) pursuant to which Explorium provides Customer access to use
Explorium’s data science platform designed to help Customer to improve its data prediction models (the
“Platform”).
In consideration of the mutual obligations set out herein, the parties hereby agree that the terms and
conditions set out below:

  1. Definitions.
    1.1. “Data Protection Laws” means, to the extent applicable to the Customer: (i) Regulation (EU)
    2016/679 General Data Protection Regulation (“GDPR”); (ii) the California Consumer Privacy Act
    of 2018, the California Privacy Rights Act of 2020 and the regulations adopted thereunder Cal.
    Civ. Code §§ 1798.100 et. seq. and 11 C.C.R §§7000 et. seq. (“California Privacy Law”).
    1.2. “SCCs” means the Annex to Commission Implementing Decision (EU) 2021/914 of 4 June 2021
    on standard contractual clauses for the transfer of personal data to third countries pursuant to
    Regulation (EU) 2016/679 of the European Parliament and of the Council, incorporated hereto
    by reference.
    1.3. Capitalized terms used in this DPA but not defined herein or in the Agreement have the meaning
    ascribed to them in the GDPR and the California Privacy Law.
  2. Scope and responsibilities.
    2.1. This DPA applies where Explorium Processes Personal Data as a Data Processor or Service
    Provider on behalf of the Customer and under the Customer’s instructions, where the Customer
    is a Data Controller subject to the GDPR with respect to the Personal Data that Explorium
    Processes, or a Business subject to the California Privacy Law with respect to the Personal
    Information that Explorium Processes. Whether the Customer is a Business as defined in the
    California Privacy Law is determined according to the provisions of the California Privacy Law
    and not this DPA. Nothing in this DPA shall be interpreted as a determination, representation,
    acknowledgment, or admission that the Customer is a Business, or that the Customer, if not
    otherwise subject to the California Privacy Law as a Business, voluntarily certifies that it is in
    compliance with and agrees to be bound by the California Privacy Law.
    2.2. Nothing in this DPA requires Explorium either to disclose to Customer or provide access to: (i)
    any data of any other customer of Explorium; (ii) Explorium’s internal accounting or financial
    information; (iii) any trade secret of Explorium; or (iv) any information that, in Explorium’s
    discretion, could compromise the security of any of Explorium’s systems or premises or cause
    Explorium to breach obligations under applicable law or its obligations to any third party.
    2.3. The Customer and Explorium are each responsible for complying with Data Protection Laws as
    applicable to them, in their roles as Data Controller (or Business (under the California Privacy
    Law) and Data Processor (or Service Provider (under the California Privacy Law), respectively.
    Customer represents and warrants to Explorium that Customer’s collection and Processing of
    the Personal Data and its provision of the Personal Data to Explorium for Processing as per this
    DPA, is made pursuant to legal basis recognized under the GDPR, fully complies with Data
    Protection Laws and will continue to comply therewith throughout the duration of the
    Customer’s use of the Platform.
    2.4. Explorium will make available to Customer all reasonable information in its disposal necessary
    to demonstrate compliance with the obligations under the Data Protection Laws.
    2.5. Explorium will assist Customer with the preparation of data privacy impact assessments and
    prior consultation as appropriate, provided, however, that if such assistance entails material
    costs or expenses to Explorium, the parties shall first come to agreement on Customer
    reimbursing Explorium for such costs and expenses.
    2.6. Explorium will provide Customer prompt notice of any request it receives from authorities to
    produce or disclose Personal Data it has Processed on Customer’s behalf, so that Customer may
    contest or attempt to limit the scope of production or disclosure request.
  3. Specifics of Processing.
    3.1. The particulars of Explorium’s Processing activities as a Processor are specified in Appendix 1.
    3.2. Explorium will Process the Personal Data only on Customer’s behalf and for as long as Customer
    instructs Explorium to do so, for the purpose of providing the Platform to the Customer.
    Explorium shall not Process the Personal Data for any other purpose. However, with respect to
    Personal Information subject to the California Privacy Law and not subject to the GDPR,
    Explorium may engage in any other Processing activities that the California Privacy Law permits
    Service Providers to engage in.
    3.3. Explorium will Process the Personal Data only on documented instructions from the Customer,
    including without limitation through the commercial agreement any applicable SOW or via the
    Platform, or as required to enrich the Customer Data pursuant to the commercial agreement
    unless Explorium is otherwise required to do so by law to which it is subject (and in such a case,
    Explorium shall inform the Customer of that legal requirement before processing, unless that
    law prohibits such information on important grounds of public interest). Customer’s instructions
    to Explorium must be consistent with the nature of character of the Platform. The Customer is
    solely responsible for determining the lawfulness of the data processing instructions it provides
    to Explorium and shall provide Explorium only instructions that are lawful under the GDPR.
    Explorium shall immediately inform the Customer if, in Explorium’s opinion, an instruction is in
    violation the GDPR or if Explorium makes a determination that it can no longer meet its
    obligations under the California Privacy Law.
    3.4. Explorium deletes the Personal Data it has Processed on Customer’s behalf under this DPA from
    its systems, shortly after the end of the term of the Agreement or upon written request from
    Customer, and upon Customer’s request, will furnish written confirmation that the Personal
    Data has been deleted pursuant to this section.

  1. Data Subject rights.
    4.1. Customer bears the sole and exclusive responsibility to comply with Data Subject rights,
    including accessing their data, correcting it, restricting its processing or deleting it. Taking into
    account the nature of Explorium’s Processing activities and the Platform, Explorium will assist
    the Customer to accommodate Data Subjects’ requests to exercise their rights in relation to
    their Personal Data. Explorium will pass on to Customer requests that it receives from Data
    Subjects regarding their Personal Data Processed by Explorium.
  2. Subprocessing.
    5.1. Customer hereby extends its general authorization to Explorium to use third party
    subprocessors for Processing Personal Data within the scope of the Platform. . The current
    subprocessors are listed in Section 4.11 of Exhibit 2. The list will also be available online.
    Explorium may update the list from time to time, adding, removing or replacing subprocessors.
    The updated list of subprocessors posted online will indicate the date on which the list has
    changed.
    5.2. Explorium will procure that the subprocessors Process the Personal Data in a manner consistent
    with Explorium’s obligations under this DPA and Data Protection Laws, particularly Article 28 of
    the GDPR, with such obligations imposed on that subprocessor by way of a written contract, in
    particular providing sufficient guarantees to implement appropriate technical and organizational
    measures in such a manner that the processing will meet the requirements of the GDPR.
    Explorium’s remains liable to the Customer for the subprocessors’ compliance with their
    obligations.
  3. Cross-border data transfers.
    6.1. Customer acknowledges and agrees that Explorium and its subprocessors will only Process the
    Personal Data in member states of the European Economic Area, in territories or territorial
    sectors recognized by an adequacy decision of the European Commission as providing an
    adequate level of protection for Personal Data pursuant to Articles 45 of the GDPR, or using
    adequate safeguards as required under the GDPR’s provisions governing cross-border data
    transfers (e.g., SCCs).
    6.2. Explorium is situated in a territory not recognized by an adequacy decision of the European
    Commission as providing an adequate level of protection for Personal Data pursuant to Articles
    45 of the GDPR. Therefore, the parties hereby enter into MODULE TWO of the SCCs, as specified
    in Appendix 2.
  4. Data security.
    7.1. In Processing Personal Data, Explorium will implement appropriate technical and organizational
    measures to protect the Personal Data against accidental or unlawful destruction or accidental
    loss, alteration, unauthorized disclosure or access, in accordance with Explorium’s ISO 27001
    and SOC-2 certifications and in accordance with Cal. Civ. Code §1798.81.5. Explorium shall
    perform regular internal or third-party assessments, audits, or other technical and operational
    testing of its security procedures and practices at least once every 12 months.
    7.2. Explorium will ensure that its staff authorized to Process the Personal Data have committed
    themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
    7.3. Explorium shall without undue delay notify Customer of any Personal Data Breach that it
    becomes aware of regarding Personal Data of Data Subjects that Explorium Processes within the
    scope of this DPA. Explorium will use commercial efforts to mitigate the breach and prevent its
    recurrence. Customer and Explorium will cooperate in good-faith on issuing any statements or
    notices regarding such breaches, to authorities and Data Subjects.
  5. Audits.
    8.1. Notwithstanding the foregoing, to the extent Explorium has undergone a third party
    independent audit based on SOC 2, Type II or similar standards, then any audit or inspection
    right exercisable by the Customer shall be first satisfied by Explorium providing the Customer
    with a report of such audit. If Customer, is not satisfied on reasonable grounds by the
    independent audit report, then Customer may request that a reputable auditor perform an
    audit or inspection pursuant to Section ‎8.2 below and Explorium shall not unreasonably deny
    that request. If Explorium nevertheless denies such audit or inspection, then Customer shall
    have the right to terminate the Agreement with immediate effect.
    8.2. Subject to Section ‎8.1 above, Explorium shall, not more than once per annum (unless otherwise
    required by a data protection authority or Data Protection Law), allow for and contribute to
    audits, including carrying out inspections conducted by a reputable auditor mandated by
    Customer, during normal business hours and subject to a prior notice to Explorium of at least 30
    days as well as appropriate confidentiality undertakings by the auditor covering such
    inspections, in order to establish Explorium’s compliance with this DPA and the provisions of the
    Data Protection Laws as regards the Personal Data that Explorium Processes on behalf of
    Customer. Such audits and inspection must reasonably limit any disruption to Explorium’s
    business, and the Customer shall avoid (and ensure that each of its auditors avoids) causing (or,
    if it cannot avoid, minimize) any damage, injury or disruption to Explorium’s premises,
    equipment, personnel and business while its personnel are on those premises in the course of
    such audit or inspection. If such audits or inspections entail material costs or expenses to
    Explorium, the parties shall first come to agreement on Customer reimbursing Explorium for
    such costs and expenses.
  6. California Privacy Law.
    This Section 9 applies to the extent that the Customer is a Business subject to the California Privacy Law.
    9.1. The Parties acknowledge and agree that Explorium is a Service Provider. The provisions of this
    DPA also apply to Explorium’s Processing of Personal Information as a Service Provider of the
    Customer.
    9.2. The Parties agree that the Customer is disclosing the Personal Information to Explorium only for
    the following limited and specified Business Purpose: the provision of Explorium’s data analysis
    and enrichment platform. Explorium shall not Sell or Share the Personal Information.
    9.3. Explorium is prohibited from retaining, using or disclosing Customer’s Personal Information for:
    9.3.1. Any commercial purpose other than the foregoing Business Purposes, unless expressly
    permitted by the California Privacy Law.
    OR
    9.3.2. Outside the direct business relationship between Customer and Explorium, unless
    expressly permitted by the California Privacy Law.
    9.4. Explorium shall comply with all applicable sections of the California Privacy Law.
    9.5. Explorium grants the Customer the right to take reasonable and appropriate steps, in
    accordance with this DPA, to ensure that the Explorium uses the Personal Information it Collects
    pursuant to this DPA in a manner consistent with Explorium’s obligations under the California
    Privacy Law.
    9.6. Explorium grants the Customer the right, upon notice, to take reasonable and appropriate steps,
    in accordance with this DPA, to stop and remediate Explorium’s unauthorized use of Personal
    Information.
    9.7. If Explorium receives a request from a California Consumer of the Customer, about his or her
    Personal Information, Explorium shall inform the Customer thereof, shall not comply with the
    request itself unless instructed to in writing by the Customer, and in the absence of Customer’s
    instructions to the contrary, shall inform the Consumer that the request cannot be acted upon
    because the request has been sent to a Service Provider.
  7. Miscellaneous.
    10.1. Explorium’s liability under this DPA shall be as per the limitations, exclusions and caps specified
    in the Agreement.
    10.2. This DPA shall prevail in the event of inconsistencies between it and the Agreement or
    subsequent agreements entered into or purported to be entered into by the parties after the
    date of this DPA – except where explicitly agreed otherwise in writing.
    10.3. This DPA is governed by the governing law specified in the Agreement, and disputes arising
    under this DPA shall be adjudicated as specified in the Agreement.
    10.4. This DPA terminated upon the termination of the Agreement.

Appendix 1

  1. Nature and purpose of the Processing

The nature and purpose of Processing is the provision of Explorium’s data science platform that helps Customer to improve its data prediction models.

  1. Duration of Processing

The duration of Processing is coterminous with the term of the Agreement and to Customer’s instructions to cease and discontinue Processing.

  1. Categories of Personal Data Processed

Names, contact details, business affiliation 

  1. Special categories of Personal Data Processed

None

  1. Categories of Data Subjects

Representatives of the customers and prospective customers of the Customer.

  1. Processing operations

The Processing operations entailed in the provision of the Platform are: organization and structuring, analysis, adaptation or alteration, storage, retrieval, consultation, use, enrichment from external sources, transmission, dissemination or otherwise making available, alignment or combination, and erasure.

Appendix 2

  1. In Section II (Obligations of the Parties), Clause 9(a) for MODULE TWO: GENERAL WRITTEN AUTHORISATION. The data importer has the data exporter’s general authorisation for the engagement of sub-processor(s) from an agreed list. 
  2. In Section IV (Final Provisions), Clause 17 for MODULE TWO: Transfer controller to processor: The parties agree that this shall be the law of Ireland.
  3. In Section IV (Final Provisions), Clause 18(b) for MODULE TWO: Transfer controller to processor: The parties agree that those shall be the courts of Ireland.
  4. In Annex I, for MODULE TWO: Transfer controller to processor:
    1. Data Exporter: Customer.
      1. Activities relevant to the data transferred under these Clauses: an organization using the Platform
      2. Role: controller
    2. Data Importer: Explorium.
      1. Activities relevant to the data transferred under these Clauses: provider and operator of the Platform.
      2. Role: processor.
    3. Description of Transfer: personal data transferred in the course of and for the purpose of providing the Platform.
    4. Categories of personal data transferred: See Appendix 1.
    5. Categories of data subjects whose personal data is transferred: See Appendix 1.
    6. Sensitive data transferred: See Appendix 1.
    7. The frequency of the transfer: ongoing.
    8. Nature of the processing: See Appendix 1.
    9. Purpose(s) of the data transfer and further processing: See Appendix 1.
    10. The period for which the personal data will be retained: See Appendix 1.
    11. Transfers to (sub-) processors:

List of Explorium Sub-Processors

Infrastructure Sub-processors

Entity NameSubprocessing ActivitiesCountry of StorageDuration of transfer 
Amazon Web ServicesCloud hosting and storageUnited StatesAs specified in 4.10 above 
Google Cloud PlatformCloud hosting and API ServicesUnited StatesAs specified in 4.10 above
Databricks Inc.Data analytics platformUnited StatesAs specified in 4.10 above
DataDogMonitoring and observabilityUnited StatesAs specified in 4.10 above
CloudFlare, Inc.Content delivery network, securityUnited StatesAs specified in 4.10 above
Pusher Ltd.Real-time messaging servicesUnited StatesAs specified in 4.10 above
Auth0 By Okta, inc.Authentication servicesUnited StatesAs specified in 4.10 above
MongoDB, Inc.Database managementUnited StatesAs specified in 4.10 above

Product Communications Sub-processors

Entity NameSubprocessing ActivitiesCountry of StorageDuration of transfer
SendGridEmail delivery serviceUnited StatesAs specified in 4.10 above
FullStorySession replay and user analyticsUnited StatesAs specified in 4.10 above
MixPanelProduct analytics platformUnited StatesAs specified in 4.10 above
HubSpotCRM and marketing automationUnited StatesAs specified in 4.10 above
Gongsales call recording, and analyticsUnited StatesAs specified in 4.10 above
Metadata, inc.marketing and campaign automation, managementUnited StatesAs specified in 4.10 above
OutreachSales engagement platformUnited StatesAs specified in 4.10 above
Zapier Inc.Workflow automationUnited StatesAs specified in 4.10 above
Zoom Video Communications, Inc.Video conferencing, virtual meetingsUnited StatesAs specified in 4.10 above
Serp.API, LLCData product United StatedAs specified in 4.10 above
Nimble, Inc. Data ProductUnited States As specified in Section 4.10 above. 
Hertza LLC (Zerobounce) Email validation United Stated/ EUAs specified in Section 4.10 above.
Open.aiLLM engineUnited States As specified in Section 4.10 above.
AnthropicLLM engineUnited States As specified in Section 4.10 above.
GeminiLLM engineUnited States As specified in Section 4.10 above.

Product Monitoring and Testing Sub-processors

Entity NameSubprocessing ActivitiesCountry of StorageDuration of transfer
AtlassianCollaboration and issue trackingUnited StatesAs specified in Section 4.10 above.
MondayProject management platformUnited StatesAs specified in Section 4.10 above.
LambdaTestCross-browser testingUnited StatesAs specified in Section 4.10 above.

Customer Support Sub-processors

Entity NameSubprocessing ActivitiesCountry of StorageDuration of transfer
Slackcommunication toolUnited StatesAs specified in Section 4.10 above.
  1. Competent Supervisory Authority: the supervisory authority in the EU member state where the data exporter is established or where its EU representative under Article 27 of the GDPR is located.
  2. In Annex II, for MODULE TWO: Transfer controller to processor: as detailed in the data importer’s ISO 27001 and SOC-2 reports and certifications (subject to data importer’s right to redact from such report any information that would identify another customer or expose confidential information of another client).