Skip to content
CodeConda
HomeAppsBlog
Sell Your App
HomeAppsBlogSell Your App

Data Processing Agreement (DPA)

Data Processing Agreement (DPA)

Last Updated: July 2026

Parties. This Data Processing Agreement (“DPA”) is between CodeConda LLC, a limited liability company organized in Arizona, United States (“CodeConda”), and the business or organization that has entered into the Main Agreement (“Customer”). Each party’s address and contact details are those in the Main Agreement, applicable order form, or Customer account records.

Execution. This DPA forms part of the Terms of Service, order form, or other agreement governing Customer’s use of the Services (the “Main Agreement”). By executing or electronically accepting the Main Agreement, or continuing to use the covered Services after receiving this DPA where permitted by the Main Agreement and applicable law, each party executes this DPA and the transfer terms incorporated in Section 9 and Schedule 4. No separate signature is required. If a separate signed DPA is required, the parties may execute a counterpart that identifies the Main Agreement.

1. Purpose and Scope

1.1 This DPA applies when and to the extent CodeConda Processes Customer Personal Data on behalf of Customer in providing the Services. “Customer Personal Data” means Personal Data submitted to, stored in, generated through, or otherwise Processed by a covered Service on Customer’s behalf.

1.2 If Customer determines the purposes and essential means of Processing, Customer is the Controller and CodeConda is its Processor. If Customer Processes Customer Personal Data for another Controller, Customer is a Processor and appoints CodeConda as its Subprocessor. References in this DPA to Customer instructions and obligations apply in either role, and Customer represents that the relevant Controller has authorized Customer to appoint CodeConda.

1.3 The Main Agreement, this DPA, Customer’s authorized configuration and use of the Services, and support requests from Customer’s authorized personnel constitute documented instructions. CodeConda shall Process Customer Personal Data only on those instructions, including for transfers, unless applicable law requires otherwise. In that event, CodeConda shall inform Customer before Processing unless the law prohibits notice on important grounds of public interest. CodeConda shall promptly inform Customer if, in its reasonable opinion, an instruction infringes applicable data protection law and may suspend the affected Processing while the parties address the issue.

1.4 CodeConda acts as an independent Controller, not a Processor under this DPA, for Personal Data it determines to Process for its own legitimate purposes, such as account administration, direct billing and tax records, relationship management, security and abuse prevention across customers, legal compliance, and establishment or defense of claims. That Processing is governed by the Privacy Policy and applicable law. CodeConda shall not recharacterize Customer Personal Data as independent-controller data merely to avoid this DPA.

1.5 This DPA does not apply to an individual’s personal or household use where the individual is the Data Subject rather than a Controller or Processor for others. The Privacy Policy governs that Processing. Nothing in this DPA limits a Data Subject’s non-waivable rights.

2. Definitions
  • “Applicable Data Protection Law” means privacy, data protection, and data security law applicable to the covered Processing, including, where applicable, the GDPR, UK GDPR, Swiss Federal Act on Data Protection, and United States state privacy laws.
  • “Controller,” “Processor,” “Process,” “Processing,” “Personal Data,” “Personal Data Breach,” and “Data Subject” have the meanings in Applicable Data Protection Law. “Controller” includes a CCPA “business,” and “Processor” includes a CCPA “service provider” or “contractor,” where relevant.
  • “EEA” means the European Economic Area. “EU SCCs” means Commission Implementing Decision (EU) 2021/914 and its standard contractual clauses, as amended or replaced.
  • “GDPR” means Regulation (EU) 2016/679. “UK GDPR” means the GDPR as incorporated into United Kingdom law.
  • “Restricted Transfer” means a transfer of Customer Personal Data requiring a transfer mechanism under the GDPR, UK GDPR, or Swiss Federal Act on Data Protection.
  • “Subprocessor” means a third party appointed by or on behalf of CodeConda to Process Customer Personal Data. It does not include Customer personnel or a third-party service that Customer directly instructs or contracts with independently of CodeConda.
  • “UK Addendum” means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses, version B1.0, issued by the UK Information Commissioner and laid before Parliament on February 2, 2022, as revised under its mandatory terms.
  • Terms not defined in this DPA have the meanings in the Main Agreement.
3. Details of Processing

3.1 The subject matter, duration, nature and purpose of Processing, categories of Personal Data, and categories of Data Subjects are set out in Schedule 1.

3.2 Customer shall not submit special-category data, highly sensitive identifiers, precise geolocation, health data, biometric data used for identification, financial account credentials, or criminal-conviction data unless the applicable Service expressly supports that data, the parties document the Processing, and Customer has satisfied all legal requirements. Customer shall not submit Personal Data concerning children in violation of the Main Agreement or Applicable Data Protection Law.

3.3 Customer is responsible for lawfulness, transparency, data minimization, accuracy, and its instructions, and for obtaining any required authorization from its Controller. CodeConda is responsible for its compliance as Processor or Subprocessor and does not assume obligations imposed on Customer solely because of Customer’s industry or independent activities.

4. Obligations of the Processor

4.1 CodeConda shall:

  • comply with Customer’s lawful documented instructions under Section 1.3;
  • ensure personnel authorized to Process Customer Personal Data are bound by confidentiality and access it only as needed for assigned duties;
  • implement and maintain the technical and organizational measures in Schedule 2;
  • comply with Section 8 when appointing Subprocessors;
  • taking into account the nature of Processing, assist Customer through appropriate measures, insofar as possible, with Data Subject requests. If CodeConda receives a request relating to Customer Personal Data, it shall direct the requester to Customer and shall not respond substantively unless Customer instructs it or law requires;
  • provide reasonable assistance, taking into account the nature of Processing and information available to CodeConda, with security, breach notification, data protection impact assessments, and prior consultations required of Customer;
  • maintain records and information reasonably necessary to demonstrate compliance with this DPA; and
  • delete or return Customer Personal Data as stated in Section 11.

4.2 Assistance requiring material effort beyond standard Service functionality may be subject to reasonable fees agreed in advance, except to the extent the assistance is required because of CodeConda’s breach of this DPA.

5. Confidentiality

5.1 CodeConda shall restrict access to Customer Personal Data to personnel and contractors with a need to know for the Services, security, support, or compliance. Authorized persons are bound by contractual or statutory confidentiality obligations that survive the end of their engagement.

6. Security Measures

6.1 CodeConda shall implement and maintain the measures in Schedule 2, designed to provide a level of security appropriate to the risk of accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data. CodeConda may update the measures to reflect technical developments, provided the overall protection is not materially reduced.

6.2 Customer is responsible for secure configuration of the Services under its control, protecting account credentials, limiting its users’ access, maintaining appropriate copies or exports where the Service does not provide archival storage, and using available security features.

7. Personal Data Breach Notification

7.1 CodeConda shall notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data. Notification will describe, as information becomes available, the nature of the breach, likely consequences, categories and approximate number of affected Data Subjects and records where known, mitigation taken or proposed, and a contact for follow-up. CodeConda may provide information in phases and shall take reasonable steps to contain, investigate, and mitigate the breach.

7.2 Notification is not an admission of fault or liability. Customer is responsible for notifications to authorities and Data Subjects unless law allocates that duty to CodeConda. CodeConda shall reasonably cooperate with Customer and shall not publicly identify Customer in a breach notice without legal requirement or Customer’s prior approval.

8. Subprocessors

8.1 Customer gives general written authorization for CodeConda to appoint the Subprocessors listed in Schedule 3 and future replacements or additions under this section. A listed Subprocessor Processes Customer Personal Data only when the relevant Service or feature uses it.

8.2 CodeConda shall enter into a written agreement with each Subprocessor imposing data protection obligations no less protective in substance than the obligations applicable to the delegated Processing under this DPA. CodeConda remains responsible to Customer for each Subprocessor’s performance to the extent required by Applicable Data Protection Law.

8.3 CodeConda shall maintain Schedule 3 on this DPA page and notify Customer’s account or administrative contact by email, in-Service notice, or another agreed channel at least fifteen (15) days before a new Subprocessor begins Processing Customer Personal Data. Customer is responsible for keeping its administrative contact current. Customer may also request notices through our support page. If advance notice is impracticable because an emergency replacement is necessary to protect security or continuity, CodeConda shall notify Customer as soon as reasonably practicable.

8.4 Customer may object within ten (10) days after notice on reasonable, documented data protection grounds specific to the new Subprocessor. The parties shall work in good faith to address the objection, including by using a commercially reasonable alternative where available. If no reasonable resolution is available, CodeConda may elect not to use the Subprocessor for Customer or Customer may terminate the affected Service by written notice before the Subprocessor begins Processing, with a refund of prepaid fees for the terminated portion after the effective termination date. This is Customer’s sole contractual remedy for a properly noticed appointment, without limiting rights under the SCCs or mandatory law.

8.5 A third-party platform or integration directly selected, instructed, or contracted by Customer is not a Subprocessor appointed by CodeConda to the extent Customer independently determines that third party’s Processing. Customer is responsible for its instructions and relationship with that third party. If CodeConda appoints the same provider to Process Customer Personal Data for CodeConda’s delivery of the Services, Schedule 3 and this section apply.

9. International Data Transfers

9.1 Customer authorizes CodeConda and its Subprocessors to Process Customer Personal Data in the United States and the locations in Schedule 3, subject to this section. Each party shall use a valid transfer mechanism for Restricted Transfers for which it is responsible.

9.2 For a Restricted Transfer governed by the GDPR, the EU SCCs are incorporated by reference and completed by Schedule 4. Module Two applies when Customer is a Controller and CodeConda is a Processor. Module Three applies when Customer is a Processor and CodeConda is its Subprocessor. The docking clause in Clause 7 applies. Option 2 in Clause 9(a) applies with the notice and objection periods in Section 8. The optional language in Clause 11(a) does not apply. In Clause 17, Option 1 applies and the governing law is the law of Ireland. Under Clause 18(b), disputes shall be resolved by the courts of Ireland.

9.3 For a Restricted Transfer governed by the UK GDPR, the EU SCCs as completed above and the UK Addendum are incorporated and completed by the UK Addendum Tables in Schedule 4. Part 2 Mandatory Clauses of the UK Addendum are incorporated without amendment. For a transfer governed by Swiss law, the EU SCCs apply with references to the GDPR understood to include the Swiss Federal Act on Data Protection, references to EU or Member State law understood to include Swiss law, the competent authority being the Swiss Federal Data Protection and Information Commissioner, and Data Subjects in Switzerland able to enforce the clauses.

9.4 The EU SCCs and UK Addendum prevail over conflicting terms of the Main Agreement or this DPA for the relevant Restricted Transfer. Nothing in this DPA varies, modifies, or overrides their mandatory text. If the European Commission, UK Information Commissioner, or other competent authority approves a replacement mechanism, CodeConda may update this section to use it on notice where legally permitted and without reducing required protection.

10. Audit and Information Rights

10.1 CodeConda shall provide information reasonably necessary to demonstrate compliance with this DPA, including relevant policies, summaries, or independent assessments actually available. CodeConda does not represent that it holds any certification not expressly identified in a current written statement.

10.2 If that information is insufficient, Customer may conduct an audit itself or through an independent auditor that is not a competitor, no more than once annually unless a Personal Data Breach, regulator request, or reasonable evidence of material noncompliance justifies more. Audits require reasonable advance notice, must occur during normal business hours, remain scoped to covered Processing, protect other customers and confidential information, and avoid unreasonable disruption. Customer bears its costs, and CodeConda may charge reasonable costs for material assistance, unless the audit identifies CodeConda’s material breach. Mandatory audit rights of a Supervisory Authority or under the SCCs are not limited.

11. Data Retention and Deletion

11.1 During the term, Customer may access, export, or delete Customer Personal Data using available Service functionality. On termination or expiry, CodeConda shall, at Customer’s choice communicated before termination or within thirty (30) days afterward, return available Customer Personal Data in a standard format where the Service supports export or delete it from active systems. If Customer does not make a timely choice, CodeConda may delete it. This period is an instruction window, not a promise that every deletion is completed within thirty days.

11.2 CodeConda may retain copies only where required by law, necessary for legal claims or security records, or present in backups and Subprocessor systems pending deletion through ordinary lifecycle processes. Retained Customer Personal Data remains protected by this DPA, is isolated from ordinary use, and is Processed only for the reason retained until deletion. CodeConda does not commit to an exact backup deletion period because infrastructure and Service lifecycles vary.

11.3 CodeConda may retain data that has been de-identified so that it cannot reasonably be linked to Customer or a Data Subject. CodeConda shall maintain technical and contractual safeguards against re-identification, shall not attempt to re-identify it except to test safeguards where permitted by law, and shall require any recipient to comply with equivalent restrictions. Merely pseudonymized data remains Customer Personal Data.

12. Liability

12.1 Each party’s liability arising from this DPA is subject to the exclusions and limitations in the Main Agreement, except that no limitation applies to the extent prohibited by Applicable Data Protection Law.

12.2 To the maximum extent permitted by law, Customer shall indemnify CodeConda against third-party claims arising from Customer’s unlawful instructions, failure to establish a lawful basis, or material breach of this DPA. This obligation does not apply to the extent caused by CodeConda’s breach, negligence, or willful misconduct.

12.3 Nothing in this DPA limits Data Subject rights, liability under the EU SCCs or UK Addendum, regulatory authority, or any liability or remedy that cannot lawfully be limited or waived.

13. Content Responsibility

13.1 Customer is responsible for the accuracy, quality, and legality of Customer Personal Data, the means by which it was obtained, notices and lawful bases, and the legality of Customer’s instructions, content, and publication of outputs.

13.2 CodeConda does not comprehensively review Customer content. CodeConda may use automated or manual systems to detect security threats, spam, fraud, abuse, or prohibited content and may investigate reports, but those systems are not guaranteed to detect every issue. Additional User Content terms appear in the Legal Disclaimers.

13.3 Customer shall ensure it has authority to instruct CodeConda and, when Customer is a Processor, shall communicate relevant Controller instructions and restrictions to CodeConda.

14. United States State Privacy Laws

14.1 This section applies to Customer Personal Data governed by the California Consumer Privacy Act, as amended (“CCPA”), or another United States state privacy law that regulates contracts between a Controller and Processor. Statutory terms have their meanings under the applicable law.

14.2 CodeConda Processes personal information for the limited and specified purposes in Schedule 1 and the Main Agreement. CodeConda shall not sell or share Customer Personal Data, retain, use, or disclose it outside the direct business relationship or for a commercial purpose other than those specified, or combine it with personal information received from another person or from CodeConda’s own interaction with a Data Subject, except as permitted by applicable law.

14.3 CodeConda shall comply with applicable restrictions, provide the same level of privacy protection required of Customer for the delegated Processing, notify Customer if CodeConda determines it can no longer meet its obligations, and allow Customer to take reasonable and appropriate steps to stop and remediate unauthorized use. Customer may monitor compliance through Section 10.

14.4 CodeConda certifies that it understands and will comply with the restrictions in this section. The parties agree that Customer makes Customer Personal Data available to CodeConda only for the limited and specified purposes in this DPA and not for monetary or other valuable consideration.

15. Miscellaneous

15.1 This DPA does not grant either party ownership of the other party’s data or intellectual property.

15.2 If a provision is invalid or unenforceable, it shall be modified to the minimum extent necessary and the remaining provisions remain effective. The EU SCCs and UK Addendum are modified only as their mandatory terms permit.

15.3 This DPA controls over the Main Agreement for covered data protection matters. The EU SCCs and UK Addendum then control for relevant Restricted Transfers. Mandatory law controls over all contractual terms.

15.4 Except where the EU SCCs, UK Addendum, or mandatory law requires otherwise, this DPA is governed by Arizona law and disputes are subject to the forum in the Main Agreement.

15.5 Amendments to this DPA follow the Main Agreement’s change procedure, except that CodeConda may update Schedule 3 under Section 8 and may update transfer terms as allowed by Section 9. No amendment reduces protection required by Applicable Data Protection Law.

16. Contact Information

16.1 Customer and Data Subjects may contact CodeConda through our support page. Customer’s privacy contact is the account administrator or contact identified in the Main Agreement, order form, or account records.

Schedule 1. Processing Details
  • Subject matter and purpose: providing, securing, maintaining, and supporting the covered Services according to Customer’s instructions, including hosting, storage, caching, proxying, translation, AI-assisted processing, generation, enrichment, delivery, authentication, troubleshooting, abuse prevention, and connected-platform operations enabled by Customer.
  • Duration and frequency: continuous or on-demand during the Main Agreement, plus restricted retention and deletion periods described in Section 11. Transfers occur as needed to provide configured features.
  • Nature of Processing: collection from Customer or its users, recording, organization, structuring, storage, adaptation, retrieval, consultation, transmission to authorized recipients, generation, combination at Customer’s instruction, restriction, return, and deletion.
  • Data Subjects: Customer personnel and authorized users; Customer’s prospects, customers, contacts, contractors, and website or service users; individuals represented in Customer content; and other Data Subjects whose data Customer submits.
  • Personal Data: names, usernames, business and personal contact details, account and authentication data, IP addresses, device and usage data, support communications, connected-account identifiers and tokens, transaction metadata, user-entered addresses or coordinates, and Personal Data in prompts, uploads, files, text, images, audio, video, translations, generated outputs, or other Customer content.
  • Sensitive data: not intentionally required as a general matter. It may be present in Customer content only when the Service expressly supports it and Customer lawfully instructs the Processing under Section 3.2. The frequency and volume are determined by Customer.
  • Return and deletion: as described in Section 11.
Schedule 2. Technical and Organizational Measures

CodeConda commits to the following measures for covered Processing, taking account of the nature, scope, context, and risk. Specific implementation varies by Service architecture.

  • Access and identity: unique workforce accounts where technically supported, role-based and least-privilege access, authentication controls, prompt revocation when access is no longer required, and periodic review of privileged access.
  • Transmission and secrets: encrypted network transport using current HTTPS/TLS configurations for supported Service connections; credentials, API keys, and production secrets stored in access-restricted configuration or secret-management facilities and not committed to public source code.
  • Stored data protection: use of infrastructure-provider storage protections and access controls, including encryption at rest where the configured provider or storage service supplies it. This is not a representation that every temporary file, cache, third-party system, or legacy component is encrypted at rest.
  • Segregation and minimization: logical separation through account, project, tenant, row-level, bucket, or equivalent authorization controls where Services are multi-tenant; collection and service access limited to data needed for configured functionality.
  • Secure development and change management: source control, review or testing proportionate to change risk, dependency and vulnerability remediation based on severity and exploitability, restricted production deployment access, and separation of development and production credentials where supported.
  • Logging, monitoring, and abuse prevention: operational and security logging appropriate to the Service, error and availability monitoring, rate limiting or bot controls where relevant, investigation of material alerts, and protection of logs from ordinary unauthorized access.
  • Availability and recovery: provider-supported redundancy and backups or recoverable managed storage where configured and appropriate to the Service, restoration procedures proportionate to risk, and continuity planning that considers critical third-party dependencies. No exact recovery time, recovery point, or backup-retention period is promised unless stated in the Main Agreement.
  • Incident response: documented channels for escalation, containment, investigation, remediation, preservation of relevant evidence, and notification under Section 7.
  • Personnel and vendor governance: confidentiality commitments, access limited by job function, security awareness appropriate to responsibilities, risk-based Subprocessor review, written data protection terms, and removal of access at the end of engagement.
  • Deletion and disposal: account or administrative deletion workflows where available, restricted retention under Section 11, and reliance on provider lifecycle deletion for backups and managed Subprocessor systems.
  • Effectiveness review: periodic review of material controls and updates in response to significant architecture, threat, incident, or legal changes.
Schedule 3. Authorized Subprocessors

The following is the authorized portfolio-wide list. Actual use depends on the Service, feature, Customer configuration, and transaction. A provider is a Subprocessor under this DPA only when CodeConda appoints it to Process Customer Personal Data on CodeConda’s behalf. CodeConda shall identify and authorize a new provider under Section 8 before that provider begins covered Processing. “United States or provider-selected region” means Processing may occur in the United States and in another region selected in the relevant Service configuration. Transfer safeguards include an adequacy decision where available, the EU SCCs and UK transfer terms, or another mechanism permitted by Applicable Data Protection Law.

  • Supabase and its applicable contracting entity, together with its infrastructure providers | authentication, managed database, storage, and backend services | Singapore, United States, or provider-selected region | account, authentication, usage, and Customer content data.
  • Cloudflare, Inc. | content delivery, network security, bot protection, DNS, and edge processing | global network, including the United States | IP, device, request, security, and transmitted content data.
  • Amazon Web Services, Inc., only where used directly or beneath a configured managed provider | cloud compute, storage, and networking | United States or provider-selected region | Customer Personal Data handled by the hosted workload.
  • Functional Software, Inc. (Sentry) | error monitoring and diagnostics | United States and provider infrastructure locations | IP, device, event, diagnostic, and limited content included in errors.
  • Google LLC, only where used directly or beneath a configured managed provider | cloud infrastructure, artificial intelligence, mapping, geocoding, and civic-data functions | United States or provider-selected region | Customer content, prompts, uploads, outputs, addresses, coordinates, queries, results, identifiers, and technical metadata.
  • OpenAI, L.L.C.; fal - Features & Labels, Inc.; and RunPod, Inc., each only for enabled features | AI model, generation, inference, and related processing | primarily United States or configured provider region | prompts, uploads, outputs, identifiers, and technical metadata.
  • DeepL SE | translation | EEA, United States, or configured provider region | submitted text, documents, translations, and technical metadata.
  • ZenLeads Inc. d/b/a Apollo.io | business-data enrichment and lookup functions | United States or provider infrastructure locations | business contact data, queries, and results.
  • Sand Dune Mail Ltd. d/b/a SMTP2GO | email delivery and delivery diagnostics | United States, EEA, New Zealand, or provider infrastructure locations | names, email addresses, message content, and delivery metadata.
  • Stripe, Inc. and PayPal, Inc., only to the extent acting as CodeConda’s Processor rather than an independent seller or Controller | payment support, fraud prevention, billing communications, and transaction operations | United States and provider infrastructure locations | identifiers, contact details, transaction metadata, and limited billing data. Full payment credentials are generally collected by the payment provider.
Schedule 4. International Transfer Terms
EU SCC Annex I.A, List of Parties

Data exporter. Customer, with the legal name, address, contact person, and contact details in the Main Agreement, order form, or account records. Activities relevant to the transfer are Customer’s use of the Services and submission of Customer Personal Data. Role: Controller under Module Two, or Processor under Module Three, as determined under Section 1.2. Signature and date: execution of the Main Agreement as described in the Execution paragraph above.

Data importer. CodeConda LLC, an Arizona limited liability company, with address and privacy contact details stated in the Main Agreement, applicable order form, or current support page. Activities relevant to the transfer are provision, security, support, and operation of the Services. Role: Processor under Module Two, or Subprocessor under Module Three. Signature and date: execution of the Main Agreement as described in the Execution paragraph above.

EU SCC Annex I.B, Description of Transfer

Categories of Data Subjects, categories of Personal Data, sensitive data and safeguards, frequency, nature and purpose, duration and retention are specified in Schedule 1. Transfers are continuous or initiated by Customer and its authorized users as needed to provide configured Services. Sensitive data is not generally intended; where lawfully submitted under Section 3.2, Schedule 2 access controls, transmission protections, minimization, logging, confidentiality, and deletion safeguards apply. The subject matter, nature, and duration of Processing by each Subprocessor are described in Schedules 1 and 3.

EU SCC Annex I.C, Competent Supervisory Authority

The competent Supervisory Authority is determined under Clause 13 of the EU SCCs. Where Customer is established in an EEA Member State, it is the authority responsible for Customer’s compliance with the GDPR for the transfer. Where Customer is not established in the EEA but falls within Article 3(2), it is the authority for Customer’s appointed representative’s Member State or, if no representative is required, the authority of the Member State where relevant Data Subjects are located. Customer shall identify that authority in the Main Agreement or provide it to CodeConda on request.

EU SCC Annex II, Technical and Organizational Measures

Schedule 2 forms Annex II to the EU SCCs. For transfers to Subprocessors, CodeConda shall select controls from Schedule 2 appropriate to the delegated Processing and contractually require the relevant Subprocessor to maintain protections no less protective in substance for that Processing.

Subprocessor Transparency

Schedule 3 provides the authorized Subprocessor list used with the general written authorization in Section 8 and Clause 9(a), Option 2 of the EU SCCs. EU SCC Annex III applies to specific authorization under Clause 9(a), Option 1 and is therefore not used here.

UK Addendum Table 1, Parties

Exporter and key contact: Customer and its privacy or account contact identified in the Main Agreement, order form, or account records. Importer and key contact: CodeConda LLC and its privacy contact available through the support page. Each party’s address is stated in the Main Agreement or applicable order form. By executing the Main Agreement, each party signs this UK Addendum on the same date and in the same manner.

UK Addendum Table 2, Selected SCCs, Modules, and Clauses

Approved EU SCCs: the EU SCCs identified in Section 2 and completed in Sections 9.2 and Schedule 4. Module Two applies to Controller-to-Processor transfers and Module Three applies to Processor-to-Processor transfers, based on Customer’s role. Clause 7 applies. Clause 9 uses Option 2 with the time periods in Section 8. Clause 11 optional redress language does not apply. Clause 17 uses Option 1 and Irish law. Clause 18 selects the courts of Ireland.

UK Addendum Table 3, Appendix Information

Annex 1A, list of parties: EU SCC Annex I.A above. Annex 1B, description of transfer: EU SCC Annex I.B and Schedule 1. Annex II, technical and organizational measures: Schedule 2. Annex III is not used because the parties selected general authorization under Clause 9(a), Option 2. Schedule 3 separately provides the authorized Subprocessor list. These materials are incorporated into the UK Addendum.

UK Addendum Table 4, Ending the Addendum on Approved Changes

Neither party may end the UK Addendum solely under Section 19 of its Mandatory Clauses when the UK Information Commissioner issues a revised Approved Addendum. The parties shall instead cooperate to implement lawfully required updates. This does not limit another termination right under the Mandatory Clauses, Main Agreement, or applicable law.

Mandatory incorporation. Part 2, Mandatory Clauses of the UK Addendum are incorporated into this DPA and apply without amendment. Defined terms in those Mandatory Clauses retain their prescribed meanings. If the information in a UK Addendum Table conflicts with a Mandatory Clause, the Mandatory Clause controls.

CodeConda

We create software people rely on.

Company

  • Apps
  • Blog
  • Sell Your App

Support

  • Contact Support
  • Accessibility

Legal

  • Terms & Policies
  • Privacy Policy
  • Terms of Service
  • Refund Policy
  • Cookie Policy
  • Acceptable Use Policy
  • Legal Disclaimers
  • Data Processing Agreement

© 2026 CodeConda LLC • All Rights Reserved