Vous devez activer les cookies pour accéder à ce site.

Get a Demo Careers Contact us AEC Glossary

Data Protection Addendum

NEWFORMA DATA PROCESSING ADDENDUM
This Data Processing Addendum (“DPA”) forms part of and is incorporated into the Master Software and Services Agreement or other agreement governing the provision of services by Supplier to Customer (the “Agreement”) entered into between:

The Customer identified in the Agreement (“Customer”);

and

The Newforma entity identified in the Agreement (“Supplier”).

Customer and Supplier are each referred to herein as a “Party” and together as the “Parties”.

This DPA applies where Supplier Processes Customer Personal Data on behalf of Customer in connection with the Services.

1. DEFINITIONS
1.1 In this DPA, the terms “Controller”, “Processor”, “Data Subject”, “Personal Data”, “Processing”, “Supervisory Authority”, “Business”, “Service Provider”, “Consumer”, “Sensitive Personal Information”, “Personal Data Breach” and equivalent terms shall have the meanings assigned to them under Applicable Data Protection Laws.

1.2 In this DPA:

“Applicable Data Protection Laws” means all laws, regulations, legally binding regulatory requirements and legally binding guidance relating to privacy, data protection, cybersecurity, confidentiality, data governance and the Processing of Personal Data, to the extent applicable to a party’s activities under this Agreement, including, without limitation:

(a) the GDPR and applicable national implementing legislation;

(b) the UK GDPR and the Data Protection Act 2018;

(c) the Swiss Federal Act on Data Protection;

(d) the California Consumer Privacy Act, as amended by the California Privacy Rights Act, and other applicable United States federal and state privacy laws;

(e) Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy legislation, including Quebec’s Act respecting the protection of personal information in the private sector, as amended by Law 25;

(f) Australia’s Privacy Act 1988 (Cth), including the Australian Privacy Principles, and applicable state and territory privacy legislation; and

(g) Singapore’s Personal Data Protection Act 2012,

together with any applicable implementing regulations, in each case as amended, extended, replaced or superseded from time to time.

“Customer Personal Data” means all Personal Data Processed by Supplier or any Subprocessor on behalf of Customer in connection with the provision of the Services.

“Restricted Transfer” means any transfer of Customer Personal Data that requires implementation of an approved transfer mechanism under Applicable Data Protection Laws.

“Security Incident” means any actual or reasonably suspected event that compromises the confidentiality, integrity, availability or resilience of Customer Personal Data or systems used to Process Customer Personal Data.

“Subprocessor” means any third party engaged by Supplier to Process Customer Personal Data on behalf of Customer.

1.3 Capitalised terms not otherwise defined in this DPA shall have the meanings assigned to them in the Agreement.

2. STATUS OF THE PARTIES
2.1 The Parties acknowledge and agree that, with respect to Customer Personal Data:

(a) Customer acts as Controller, Business or equivalent regulated entity;

(b) Supplier acts as Processor, Service Provider or equivalent regulated entity; and

(c) Supplier acts solely as a Processor or Service Provider in respect of Customer Personal Data.

2.2 Nothing in this DPA shall prevent Supplier from Processing Personal Data for which Supplier acts as an independent Controller, provided that such Processing is separate from and does not involve Customer Personal Data Processed under the Agreement.

2.3 Each Party shall comply with its respective obligations under Applicable Data Protection Laws.

3. PROCESSING OF CUSTOMER PERSONAL DATA
3.1 Supplier shall Process Customer Personal Data only:

(a) for the purpose of providing the Services and fulfilling its obligations under the Agreement;

(b) in accordance with this DPA;

(c) in accordance with Customer’s documented instructions; or

(d) where required to do so by applicable law.

3.2 Where Supplier is required by law to Process Customer Personal Data other than on Customer’s instructions, Supplier shall inform Customer of that legal requirement before such Processing occurs unless prohibited by law.

3.3 Supplier shall immediately notify Customer if Supplier reasonably believes that any instruction received from Customer infringes Applicable Data Protection Laws.

3.4 Supplier shall not:

(a) sell Customer Personal Data;

(b) share Customer Personal Data for cross-context behavioural advertising;

(c) use Customer Personal Data for targeted advertising purposes;

(d) disclose Customer Personal Data except as permitted by this DPA or required by law; or

(e) Process Customer Personal Data for any purpose other than those expressly authorised by Customer.

4. CONFIDENTIALITY
4.1 Supplier shall ensure that all personnel authorised to Process Customer Personal Data are subject to enforceable obligations of confidentiality and receive appropriate training concerning the protection of Personal Data.

4.2 Supplier shall ensure that access to Customer Personal Data is limited to those personnel who require such access for the performance of their duties in connection with the Services.

4.3 Supplier shall ensure that confidentiality obligations survive termination of employment, engagement or access rights.

5. SECURITY OF PROCESSING
5.1 Supplier shall implement and maintain appropriate technical and organisational measures designed to ensure a level of security appropriate to the risk associated with the Processing of Customer Personal Data.

5.2 In determining the appropriate level of security, Supplier shall take into account the nature, scope, context and purposes of Processing, the risks presented by the Processing, the likelihood and severity of harm to Data Subjects, the state of the art and the costs of implementation.

5.3 Supplier shall maintain a documented information security programme that is designed to preserve the confidentiality, integrity, availability and resilience of Customer Personal Data and systems used to Process Customer Personal Data.

5.4 Without limiting Section 5.1, Supplier shall maintain measures addressing identity and access management, authentication, privilege management, encryption, vulnerability management, malware protection, logging, monitoring and personnel security.

5.5 Supplier shall periodically test, assess and evaluate the effectiveness of its technical and organisational measures and shall implement improvements where reasonably necessary.

6. SECURITY INCIDENTS AND PERSONAL DATA BREACHES
6.1 Supplier shall notify Customer without undue delay and, where reasonably practicable, within twenty four (24) hours after becoming aware of a Personal Data Breach affecting Customer Personal Data.

6.2 Supplier’s notification shall include all information reasonably available to Supplier concerning:

(a) the nature of the Personal Data Breach;

(b) the categories and approximate number of affected Data Subjects;

(c) the categories and approximate volume of Customer Personal Data affected;

(d) the likely consequences of the Personal Data Breach;

(e) measures taken or proposed to mitigate the effects of the Personal Data Breach; and

(f) contact information for Supplier’s incident response personnel.

6.3 Supplier shall promptly investigate the Personal Data Breach and take reasonable measures to contain, mitigate and remediate the Personal Data Breach.

6.4 Supplier shall reasonably cooperate with Customer regarding any notification obligations, investigations or remediation activities arising from the Personal Data Breach.

7. DATA SUBJECT RIGHTS
7.1 Taking into account the nature of the Processing, Supplier shall provide reasonable assistance to Customer in responding to requests from Data Subjects exercising rights under Applicable Data Protection Laws.

7.2 If Supplier receives a request directly from a Data Subject relating to Customer Personal Data, Supplier shall promptly notify Customer and shall not respond to such request except upon Customer’s documented instructions or as required by applicable law.

8. ASSISTANCE OBLIGATIONS
8.1 Supplier shall provide Customer with reasonable assistance necessary to enable Customer to comply with its obligations under Applicable Data Protection Laws.

8.2 Such assistance shall include assistance relating to:

(a) data protection impact assessments;

(b) transfer impact assessments;

(c) consultations with Supervisory Authorities;

(d) compliance with Articles 32 to 36 of the GDPR and equivalent provisions under other Applicable Data Protection Laws; and

(e) investigations conducted by Supervisory Authorities.

9. SUBPROCESSORS
9.1 Customer hereby grants Supplier a general authorisation to engage Subprocessors in connection with the provision of the Services.

9.2 Supplier shall not engage a Subprocessor unless Supplier has entered into a written agreement imposing obligations on the Subprocessor that provide substantially the same level of protection for Customer Personal Data as those set out in this DPA.

9.3 Supplier shall remain fully responsible for the performance of each Subprocessor’s obligations and for the acts and omissions of each Subprocessor.

9.4 Supplier shall maintain an up-to-date list of Subprocessors and shall make such list available to Customer upon request or through an online portal.

9.5 Supplier shall provide at least thirty (30) days’ prior notice of any intended appointment or replacement of a Subprocessor that will Process Customer Personal Data.

9.6 Customer may object to the appointment of a proposed Subprocessor on reasonable data protection grounds by providing written notice during the applicable notice period.

9.7 Where Customer raises a reasonable objection, the Parties shall work together in good faith to identify a commercially reasonable solution. If no such solution can be implemented, Customer may terminate the affected Services upon written notice without penalty.

10. INTERNATIONAL TRANSFERS
10.1 Supplier shall not transfer Customer Personal Data internationally unless such transfer complies with Applicable Data Protection Laws.

10.2 The Parties shall implement the transfer mechanisms described in Schedules 4 and 5 where required under Applicable Data Protection Laws.

10.3 Supplier shall implement supplementary technical, organisational and contractual safeguards where required by Applicable Data Protection Laws.

11. GOVERNMENT ACCESS REQUESTS
11.1 To the extent legally permitted, Supplier shall promptly notify Customer of any legally binding request from a governmental authority, regulator, law enforcement body or court seeking access to Customer Personal Data.

11.2 Supplier shall take reasonable steps to challenge any request that Supplier reasonably believes to be unlawful, invalid or disproportionate.

11.3 Supplier shall disclose only the minimum amount of Customer Personal Data required to satisfy a legally binding request.

12. AUDITS
12.1 Supplier shall make available to Customer all information necessary to demonstrate compliance with this DPA and Supplier’s applicable obligations under Applicable Data Protection Laws.

12.2 Supplier may satisfy its obligations under Section 12.1 through the provision of independent audit reports, security certifications, penetration testing summaries, responses to security questionnaires or equivalent documentation, to the extent such materials adequately demonstrate the relevant compliance.

12.3 Where the information provided under Section 12.2 is insufficient to demonstrate the relevant compliance, or otherwise to the extent required by Applicable Data Protection Laws, Supplier shall allow for and contribute to audits, including inspections, conducted by Customer or an independent auditor mandated by Customer. Such audits shall:

(a) be limited to the processing of Personal Data on behalf of Customer and Supplier’s compliance with this DPA and Applicable Data Protection Laws;

(b) be conducted on reasonable prior written notice, during normal business hours and in a manner that minimises disruption to Supplier’s operations;

(c) be subject to appropriate confidentiality obligations and reasonable security requirements; and

(d) take account of the information already provided under Section 12.2 and avoid unnecessary duplication.

Customer shall not exercise these audit rights more than once in any twelve-month period unless an additional audit is reasonably necessary following a Personal Data Breach affecting Customer’s Personal Data, reasonable evidence of material non-compliance, or a requirement of Applicable Data Protection Laws or a competent supervisory authority.

Supplier may protect information relating to other customers and information unrelated to the audit, provided that doing so does not prevent Customer from exercising its rights under Applicable Data Protection Laws. Nothing in this Section 12 shall restrict the powers of a competent supervisory authority or any mandatory audit or inspection rights under Applicable Data Protection Laws.

13. RECORDS OF PROCESSING
Supplier shall maintain records of Processing activities as required under Applicable Data Protection Laws and shall make such records available to competent regulatory authorities where legally required.

14. BUSINESS CONTINUITY AND DISASTER RECOVERY
Supplier shall maintain documented business continuity and disaster recovery plans designed to support the continued availability and recovery of Customer Personal Data and critical systems used in connection with the Services.

Supplier shall periodically test such plans and update them as necessary.

15. RETURN AND DELETION OF DATA
15.1 Upon termination or expiry of the Agreement, Supplier shall, at Customer’s election, return or securely delete Customer Personal Data.

15.2 Supplier shall complete deletion in accordance with the deletion requirements and timescales set out in the Agreement, including the permitted retention exceptions and associated safeguards, unless earlier deletion is required by Applicable Data Protection Laws..

15.3 Upon Customer’s written request, Supplier shall provide written certification confirming deletion.

15.4 Supplier may retain Customer Personal Data to the extent required by applicable law, legal hold obligations, regulatory requirements, disaster recovery requirements or legitimate archival obligations, provided that such retained data remains protected in accordance with this DPA.

16. US STATE PRIVACY LAW PROVISIONS
16.1 To the extent applicable United States privacy laws apply, Supplier acknowledges that it acts as a Service Provider and/or Processor with respect to Customer Personal Data.

16.2 Supplier shall not retain, use or disclose Customer Personal Data other than as necessary to perform the Services, comply with applicable law or otherwise as permitted under Applicable Data Protection Laws.

16.3 Supplier certifies that it understands and shall comply with the restrictions applicable to Service Providers and Processors under applicable United States privacy laws.

17. LIABILITY
The liability of each Party arising under or in connection with this DPA shall be subject to the exclusions, limitations and liability caps set out in the Agreement, except to the extent such limitations are prohibited by Applicable Data Protection Laws.

18. TERM AND SURVIVAL
This DPA shall commence on the Effective Date of the Agreement and shall remain in effect for so long as Supplier Processes Customer Personal Data on behalf of Customer.

19. ORDER OF PRECEDENCE
In the event of any conflict between this DPA and the Agreement, this DPA shall prevail with respect to matters relating to the Processing of Customer Personal Data. Where any applicable transfer mechanism conflicts with this DPA, the transfer mechanism shall prevail to the extent of such conflict.

20. GOVERNING LAW
This DPA shall be governed by the governing law specified in the Agreement except where Applicable Data Protection Laws require otherwise.

SCHEDULE 1
DETAILS OF PROCESSING
This Schedule forms Annex I to the EU Standard Contractual Clauses and forms part of the Data Processing Addendum.

A. LIST OF PARTIES
Data Exporter
The Data Exporter is the Customer identified in the Agreement.

The Data Exporter acts as a Controller, Business or equivalent regulated entity in relation to Customer Personal Data Processed pursuant to the Agreement.

The Data Exporter’s contact details shall be those specified in the Agreement or applicable Order Form.

Data Importer
The Data Importer is the Supplier identified in the Agreement, where it receives the relevant international transfer of Personal Data. Where Personal Data is transferred to Supplier Affiliates acting as a Subprocessor, that entity shall be the Data Importer for the relevant transfer and shall be identified in the applicable transfer documentation.

Supplier shall ensure that each such Affiliate is appointed in accordance with this DPA’s Subprocessor provisions and that the transfer is covered by a valid transfer mechanism under Applicable Data Protection Laws. Supplier shall remain responsible for its Affiliates’ performance of their Subprocessor obligations under this DPA.

The Data Importer acts as a Processor, Service Provider or equivalent regulated entity in relation to Customer Personal Data Processed pursuant to the Agreement.

The Data Importer’s contact details shall be those specified in the Agreement or applicable Order Form.

B. DESCRIPTION OF TRANSFER
Subject Matter of Processing
The Processing of Customer Personal Data in connection with the provision, operation, maintenance, support, security, administration and improvement of the Services.

Duration of Processing
Customer Personal Data shall be Processed for the duration of the Agreement and for any period thereafter during which Supplier is required to retain Customer Personal Data in accordance with the Agreement, Customer instructions or Applicable Data Protection Laws.

Nature of Processing
Supplier may Process Customer Personal Data through activities including collection, recording, organisation, structuring, storage, adaptation, retrieval, consultation, use, transmission, disclosure, analysis, support, maintenance, deletion and destruction.

Purpose of Processing
The purposes of Processing include:

the provision of the Services;

management of Customer accounts and subscriptions;

hosting and storage of Customer Content;

authentication and access management;

technical support;

system administration;

information security;

service monitoring;

service maintenance;

business continuity and disaster recovery;

compliance with legal and regulatory obligations; and

such other Processing activities as are reasonably necessary to provide the Services.

Categories of Data Subjects
Customer personnel;

employees;

officers;

directors;

contractors;

consultants;

temporary workers;

agents;

clients;

customers;

prospective customers;

end users;

authorised users;

business contacts; and

such other categories of individuals whose Personal Data is submitted to the Services by or on behalf of Customer.

Categories of Personal Data
Identification data;

name;

title;

job role;

business contact details;

email addresses;

telephone numbers;

postal addresses;

account information;

authentication credentials;

login information;

device identifiers;

IP addresses;

usage information;

communications data;

project information;

workflow information;

transaction records;

support records;

audit logs; and

any other Personal Data uploaded, submitted or otherwise made available by Customer through the Services.

Special Category Data
Supplier does not require the submission of Special Category Data for operation of the Services.

To the extent Customer submits Special Category Data, such Processing shall occur solely in accordance with Customer’s instructions and the Agreement.

Frequency of Transfer
Customer Personal Data may be transferred on a continuous basis during Customer’s use of the Services.

Retention Period
Customer Personal Data shall be retained in accordance with the Agreement and Supplier’s documented retention procedures, unless otherwise required by Applicable Data Protection Laws.

Competent Supervisory Authority
The competent Supervisory Authority shall be determined in accordance with Applicable Data Protection Laws.

SCHEDULE 2
TECHNICAL AND ORGANISATIONAL MEASURES
Supplier shall implement and maintain technical and organisational measures designed to ensure a level of security appropriate to the risks associated with the Processing of Customer Personal Data.

Information Security Governance
Supplier shall maintain a documented information security management programme supported by policies, standards and procedures governing the protection of Customer Personal Data.

Supplier shall assign responsibility for information security to appropriately qualified personnel and shall periodically review the effectiveness of its security programme.

Access Management
Supplier shall implement identity and access management controls designed to ensure that access to Customer Personal Data is restricted to authorised personnel on a need-to-know basis.

Access rights shall be granted, reviewed and revoked through documented procedures.

Privileged access shall be subject to enhanced controls and monitoring.

Multi-factor authentication shall be implemented for administrative access and remote access to systems Processing Customer Personal Data where technically feasible.

Encryption
Supplier shall protect Customer Personal Data during transmission across public networks through the use of industry-standard encryption protocols.

Supplier shall implement encryption at rest for Customer Personal Data where appropriate taking into account the nature and sensitivity of the information Processed.

Supplier shall maintain procedures governing the management and protection of encryption keys.

System Security
Supplier shall maintain controls designed to protect systems against malicious software, unauthorised access and exploitation of known vulnerabilities.

Supplier shall maintain documented vulnerability management procedures and shall apply security patches within timeframes appropriate to the severity of identified vulnerabilities.

Monitoring and Logging
Supplier shall maintain logging and monitoring capabilities designed to identify security events affecting Customer Personal Data.

Audit logs shall be protected against unauthorised modification and retained in accordance with Supplier’s security policies.

Secure Development
Where Supplier develops software used to provide the Services, Supplier shall maintain secure software development practices designed to identify and mitigate security vulnerabilities throughout the software development lifecycle.

Incident Management
Supplier shall maintain documented procedures for identifying, escalating, investigating, responding to and remediating Security Incidents.

Supplier shall periodically review and test incident response procedures.

Business Continuity
Supplier shall maintain business continuity and disaster recovery plans designed to support the continued availability and recovery of Customer Personal Data and critical service functions.

Supplier shall periodically test such plans and maintain records of testing activities.

Personnel Security

Supplier shall provide privacy and security training to personnel authorised to Process Customer Personal Data.

Where permitted by law and appropriate to the role performed, Supplier may conduct pre-employment screening of personnel.

Physical Security
Supplier shall implement reasonable physical security measures designed to prevent unauthorised physical access to facilities used to Process Customer Personal Data.

Where hosting services are provided through third-party cloud infrastructure providers, Supplier shall conduct reasonable due diligence regarding the physical security controls maintained by such providers.

Testing and Evaluation
Supplier shall periodically assess, test and evaluate the effectiveness of its technical and organisational measures and shall implement improvements where necessary to address evolving threats and risks.

SCHEDULE 3

AUTHORISED SUBPROCESSORS
The current Subprocessor register is available at:

https://trust.newforma.com/

SCHEDULE 4

EUROPEAN UNION STANDARD CONTRACTUAL CLAUSES IMPLEMENTATION SCHEDULE
1. INCORPORATION OF THE SCCS
To the extent that Customer Personal Data originating from the European Economic Area is transferred to a jurisdiction that has not been recognised by the European Commission as providing an adequate level of protection for Personal Data, the Parties agree that the Standard Contractual Clauses approved by European Commission Implementing Decision (EU) 2021/914 (the “EU SCCs”) are incorporated into and form part of this DPA.

The Parties agree that the applicable module of the EU SCCs shall be determined by the role of the Parties in the relevant Processing activity. Where Customer acts as Controller and Supplier acts as Processor, Module Two (Controller to Processor) shall apply. Where Supplier transfers Customer Personal Data to a Subprocessor acting as Processor, Module Three (Processor to Processor) shall apply.

2. COMPLETION OF THE SCCS
For purposes of Clause 7 of the SCCs, the optional docking clause shall apply.

For purposes of Clause 9, Option 2 shall apply and the time period for prior notice of Subprocessor changes shall be thirty (30) days.

For purposes of Clause 11, the optional independent dispute resolution mechanism shall not apply unless otherwise required by applicable law.

For purposes of Clauses 17 and 18, the governing law and competent courts shall be the governing law and courts of Ireland unless otherwise specified in an Order Form or required by Applicable Data Protection Laws.

3. TECHNICAL AND ORGANISATIONAL MEASURES
The technical and organisational measures described in Schedule 2 shall constitute the measures required under Annex II of the SCCs.

4. SUBPROCESSORS
The list of authorised Subprocessors maintained pursuant to Schedule 3 shall constitute Annex III of the SCCs.

5. TRANSFER IMPACT ASSESSMENTS
Supplier confirms that it has not knowingly received any request from a public authority for access to Customer Personal Data that would prevent Supplier from complying with the SCCs.

Supplier shall monitor legal developments affecting international transfers and shall cooperate with Customer in conducting transfer impact assessments where required.

6. SUPPLEMENTARY SAFEGUARDS
Supplier shall implement supplementary safeguards where required, including encryption, access controls, data minimisation, audit logging, organisational controls and contractual commitments designed to mitigate risks arising from access by public authorities.

SCHEDULE 5
UNITED KINGDOM INTERNATIONAL DATA TRANSFER ADDENDUM
1. INCORPORATION
The International Data Transfer Addendum issued by the UK Information Commissioner’s Office under section 119A of the Data Protection Act 2018 (the “UK Addendum”) is incorporated into this DPA and applies to Restricted Transfers subject to the UK GDPR.

2. INTERPRETATION
The EU SCCs incorporated into Schedule 4 shall constitute the Approved EU SCCs for purposes of the UK Addendum.

The Parties agree that the information required for Tables 1 to 4 of the UK Addendum shall be completed as follows:

The Parties are identified in the Agreement and this DPA.

The transfer description shall be as set out in Schedule 1.

The security measures shall be those described in Schedule 2.

Neither Party shall terminate the UK Addendum under Section 19 thereof except where legally entitled to do so.

3. UK TRANSFER OBLIGATIONS
Supplier shall implement and maintain all safeguards necessary to ensure that Customer Personal Data transferred outside the United Kingdom receives a level of protection essentially equivalent to that guaranteed under UK Data Protection Laws.

Supplier shall promptly notify Customer if Supplier determines that it can no longer comply with the UK Addendum or any applicable transfer mechanism.

4. CONFLICT
In the event of conflict between the UK Addendum and any other provision of the DPA, the UK Addendum shall prevail to the extent necessary to ensure lawful international transfers.

SCHEDULE 6
ARTIFICIAL INTELLIGENCE AND DATA GOVERNANCE SCHEDULE

1. PURPOSE
This Schedule governs the use of Customer Personal Data in connection with artificial intelligence systems, machine learning technologies, automated decision-making tools and similar technologies utilised by Supplier.

2. RESTRICTIONS ON TRAINING
Except to the extent expressly permitted under the AI terms of the Agreement or otherwise expressly authorised in writing by Customer, Supplier shall not use Customer Personal Data, Customer Confidential Information, Customer Content, or any prompts, outputs, metadata or information derived from them to train, retrain, fine-tune, improve or otherwise develop any foundation model, large language model, machine learning model or other artificial intelligence system. Any permitted use shall remain subject to the restrictions and safeguards set out in the AI terms of the Agreement, this DPA and applicable Data Protection Laws. Any consent granted by Customer under this Section shall be specific, informed and documented in writing.

3. MODEL DEVELOPMENT
Supplier shall ensure that Customer Personal Data is logically segregated from datasets used for model development and training except where Customer has expressly authorised such use.

Supplier shall maintain technical controls designed to prevent unauthorised use of Customer Personal Data for model training purposes.

4. HUMAN OVERSIGHT
Where Supplier utilises artificial intelligence systems that materially affect the Services, Supplier shall implement appropriate human oversight measures designed to monitor the operation, performance and outcomes of such systems.

Supplier shall maintain procedures for reviewing, investigating and correcting inaccurate, biased or inappropriate outputs generated by such systems.

5. TRANSPARENCY
Upon Customer’s reasonable request, Supplier shall provide information regarding the categories of artificial intelligence systems used in connection with the Services and the purposes for which such systems are used.

Nothing in this Section shall require Supplier to disclose trade secrets, source code or proprietary algorithms.

6. AUTOMATED DECISION-MAKING
Supplier shall not knowingly use Customer Personal Data to make solely automated decisions producing legal or similarly significant effects on individuals unless expressly authorised by Customer and permitted by Applicable Data Protection Laws.

7. AI SECURITY CONTROLS
Supplier shall implement technical and organisational measures designed to mitigate risks associated with artificial intelligence systems, including risks relating to data leakage, prompt injection, model inversion, unauthorised access, model manipulation and unauthorised disclosure of Customer Personal Data.

8. REGULATORY COMPLIANCE
Supplier shall comply with all applicable laws governing artificial intelligence systems, automated decision-making technologies and algorithmic accountability.

Where applicable, Supplier shall cooperate with Customer regarding compliance with the EU AI Act, UK AI regulatory requirements and other applicable artificial intelligence regulations.

9. AUDIT RIGHTS
Customer’s audit and information rights under Section 12 shall apply to this Schedule.