Data Transfers If Lenovo or its Subcontractors are located outside the EEA, Lenovo and Controller hereby execute the controller to processor standard contractual clauses as set out in MODULE TWO in the Commission Implementing Decision (EU) 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council as amended or superseded from time to time (the "C2P Standard Contractual Clauses") and hereby incorporate them into this Addendum by reference. The parties acknowledge and agree that: a. Lenovo and Controller shall each comply with their respective obligations in the C2P Standard Contractual Clauses; b. If there is any conflict or inconsistency between the C2P Standard Contractual Clauses and this Addendum or the Agreement, the C2P Standard Contractual Clauses shall control to the extent of the conflict; and c. The information in the following tables is hereby incorporated into the C2P Standard Contractual Clauses between the Parties: Clause 9. Use of sub-processors Option 2 GENERAL WRITTEN AUTHORISATION is selected. Data importer shall provide information at least 30 days in advance as per Clause “Subprocessing” Clause 17. Governing law These Clauses shall be construed in accordance with the governing law set forth in the Parties’ base agreement unless that governing law is not that of an EU Member State that allows for third-party beneficiary rights. In such event, the Parties agree that these Clauses shall be governed by the law of IRELAND. Clause 18 (b). Choice of forum and jurisdiction The Parties agree that any dispute arising from these Clauses shall be resolved by the courts of IRELAND. Data Exporter’s Name Controller, and any of its commonly owned or controlled affiliates Data Exporter’s Address The address of the Customer entity that entered into the Agreement. Data Exporter´s contact person´s name, position and contact details As agreed as part of the Agreement. Data Exporter´s activities relevant to the data transferred under these Clauses The Services provided by the Data Importer to the Data Exporter in accordance with the Agreement Data Exporter´s signature and date The parties agree that acceptance of the Agreement by the Data Importer and the Data Exporter has the equivalent legal effect of a signature. The date of signature is the date of such acceptance Data Exporter´s role Controller Data Importer’s name Lenovo and its subcontractors Data Importer´s address The address of the Lenovo entity that is providing the Services Data Importer´s contact details xxxx@xxxxxx.xxx Data Importer´s activities relevant to the data transferred under these Clauses The Services provided by the Data Importer to the Data Exporter in accordance with the Agreement Data Importer´s signature and date The parties agree that acceptance of the Agreement by the Data Importer and the Data Exporter has the equivalent legal effect of a signature. The date of signature is the date of such acceptance Data Importer’s Role Processor Categories of data subjects As set out in Exhibit A Categories of personal data As set out in Exhibit A Sensitive data As set out in Exhibit A Frequency of the Transfer As required for the provision of the Services Nature of the processing As set out in Exhibit A Purpose of the processing As set out in Exhibit A Period for which personal data will be retained As set out in Exhibit A Subject matter, nature and duration of the processing carried out by subprocessors As set out in Exhibit A Competent Supervisory Authority with responsibility for ensuring compliance by the data exporter with Regulation (EU) 2016/679 ty The supervisory authority that will act as competent supervisory authority will be that of the EU member State where Data Exporter is established in the EU. If Data Exporter (i.e., contracting legal entity) is not established in EU, then the Competent Supervisory Authority will be such of the EU Member State in which the Data Exporter´s EU representative within the meaning of Article 27(1) of Regulation (EU) 2016/679 is established. If the Data Exporter is not established in the EU but does not need to appoint an EU representative, then the Competent Supervisory Authority will be that of the EU Member State in which the data subjects whose personal data is transferred under these Clauses in relation to the offering of goods or services to them, or whose behaviour is monitored, are located. Description of the technical and organisational measures implemented by the data importer(s) (including any relevant certifications) to ensure an appropriate level of security, taking into account the nature, scope, context and purpose of the processing, and the risks for the rights andfreedoms of natural persons. Set forth at Section 11 of this Addendum and in its Exhibit A. List of authorised subprocessors As set out in Annex 1 to Exhibit A
International Data Transfers The Company and the Stock Plan Administrator are based in the United States. The Participant should note that the Participant’s country of residence may have enacted data privacy laws that are different from the United States. The Company’s legal basis for the transfer of the Participant's Personal Information to the United States is the Participant’s consent.
Data Transfer 11.1 The Processor may not transfer or authorize the transfer of Data to countries outside the EU and/or the European Economic Area (EEA) without the prior written consent of the Company. If personal data processed under this Agreement is transferred from a country within the European Economic Area to a country outside the European Economic Area, the Parties shall ensure that the personal data are adequately protected. To achieve this, the Parties shall, unless agreed otherwise, rely on EU approved standard contractual clauses for the transfer of personal data.
Data Subjects The categories of Data Subjects who we may collect Personal Data about may include the following where they are a natural person: the Customer, the directors and ultimate beneficial owner(s) of the Customer, your customers, employees and contractors, payers and payees. You may share with Airwallex some or all of the following types of Personal Data regarding Data Subjects: • full name; • email address; • phone number and other contact information; • date of birth; • nationality; • public information about the data subject; • other relevant verification or due diligence documentation as required under these terms; and • any other data that is necessary or relevant to carry out the Agreed Purposes.
New Countries The Fund shall be responsible for informing the Custodian sufficiently in advance of a proposed investment which is to be held in a country in which no Subcustodian is authorized to act in order that the Custodian shall, if it deems appropriate to do so, have sufficient time to establish a subcustodial arrangement in accordance herewith. In the event, the Custodian is unable to establish such arrangements prior to the time the investment is to be acquired, the Custodian is authorized to designate at its discretion a local safekeeping agent, and the use of the local safekeeping agent shall be at the sole risk of the Fund, and accordingly the Custodian shall be responsible to the Fund for the actions of such agent if and only to the extent the Custodian shall have recovered from such agent for any damages caused the Fund by such agent.
Data Subject Rights (a) The data importer shall promptly notify the data exporter of any request it has received from a data subject. It shall not respond to that request itself unless it has been authorised to do so by the data exporter. (b) The data importer shall assist the data exporter in fulfilling its obligations to respond to data subjects’ requests for the exercise of their rights under Regulation (EU) 2016/679. In this regard, the Parties shall set out in Annex II the appropriate technical and organisational measures, taking into account the nature of the processing, by which the assistance shall be provided, as well as the scope and the extent of the assistance required. (c) In fulfilling its obligations under paragraphs (a) and (b), the data importer shall comply with the instructions from the data exporter.
Data Export Except as permitted in writing by Citizens’ Contract Manager or designee, Vendor and Vendor Staff are prohibited from: (a) performing any Services outside of the United States; or, (b) sending, transmitting, or accessing any Citizens Confidential Information outside of the United States.
Categories of Data Subjects Any individual accessing and/or using the Services through the Customer's account ("Users"); and any individual: (i) whose email address is included in the Customer's Distribution List; (ii) whose information is stored on or collected via the Services, or (iii) to whom Users send emails or otherwise engage or communicate with via the Services (collectively, "Subscribers").
Third Party Data Any statistical, industry-related and market-related data, which are included in the Disclosure Package and the Prospectus, is based on or derived from sources that the Company reasonably and in good faith believes to be reliable and accurate, and such data agrees with the sources from which it is derived, and the Company has obtained the written consent for the use of such data from such sources to the extent required.
Security and Data Transfers Party shall comply with all applicable State and Agency of Human Services' policies and standards, especially those related to privacy and security. The State will advise the Party of any new policies, procedures, or protocols developed during the term of this agreement as they are issued and will work with the Party to implement any required. Party will ensure the physical and data security associated with computer equipment, including desktops, notebooks, and other portable devices, used in connection with this Agreement. Party will also assure that any media or mechanism used to store or transfer data to or from the State includes industry standard security mechanisms such as continually up-to-date malware protection and encryption. Party will make every reasonable effort to ensure media or data files transferred to the State are virus and spyware free. At the conclusion of this agreement and after successful delivery of the data to the State, Party shall securely delete data (including archival backups) from Party’s equipment that contains individually identifiable records, in accordance with standards adopted by the Agency of Human Services. Party, in the event of a data breach, shall comply with the terms of Section 7 above.