Securing 2M+ accounts & $15B+ in assets, protected & secure·B5 Secure™ — per data-element authorization for .NET platforms

Data Processing Addendum

Legal · Data Processing Addendum · v.260624

Data Processing Addendum

The DPA and Standard Contractual Clauses for customers who need a processor agreement for personal data handled in connection with B5 Secure. Counter-signed by both parties — download the signature-ready PDF below.

← Legal & agreements  ·  Download PDF →

This Data Processing Addendum (this “DPA”) forms part of the agreement between B5 SECURE LLC (“B5 Secure”) and the customer that executes it (“Customer”) for Customer’s use of B5 Secure software and services (the “Agreement”), and applies where B5 Secure processes Personal Data on Customer’s behalf. Context: the B5 Secure software is a library that runs inside Customer’s own environment; B5 Secure does not access or process Customer’s end-user Personal Data through the software and is not a processor of that data by virtue of the license. This DPA governs the limited processing B5 Secure performs on Customer’s behalf (for example, in connection with support or license administration) or that the parties otherwise agree is in scope.

1.Definitions and Roles

“Controller,” “Processor,” “Personal Data,” “Processing,” “Data Subject,” and “Personal Data Breach” have the meanings in Applicable Data Protection Law (including the EU and UK GDPR and the CCPA/CPRA). For Personal Data B5 Secure processes on Customer’s behalf, Customer (or its own customer) is the Controller and B5 Secure is the Processor (a “service provider” under the CCPA/CPRA). “SCCs” means the Standard Contractual Clauses in Commission Implementing Decision (EU) 2021/914.

2.Scope and Applicability

This DPA applies only to B5 Secure’s Processing of Customer Personal Data as a Processor. It does not apply to Personal Data that Customer processes within its own environment using the software, for which Customer is the Controller and B5 Secure has no access. Annex I describes the in-scope Processing.

3.Processing on Instructions

B5 Secure will process Customer Personal Data only on Customer’s documented instructions, including as set out in the Agreement and this DPA, and as necessary to comply with law (in which case B5 Secure will inform Customer unless legally prohibited). B5 Secure will not sell or share Customer Personal Data or process it for any purpose other than performing the services.

4.Confidentiality

B5 Secure will ensure that personnel authorized to process Customer Personal Data are bound by appropriate confidentiality obligations and process the data only as instructed.

5.Security

B5 Secure will implement and maintain the technical and organizational measures described in Annex II, appropriate to the risk, to protect Customer Personal Data.

6.Sub-processors

Customer provides general authorization for B5 Secure to engage Sub-processors to support the services, listed in Annex III. B5 Secure will impose data-protection obligations on each Sub-processor no less protective than those in this DPA and remains responsible for their performance. B5 Secure will give Customer prior notice of any intended addition or replacement of a Sub-processor and a reasonable opportunity to object on reasonable data-protection grounds.

7.Data-Subject Requests

Taking into account the nature of the Processing, B5 Secure will provide reasonable assistance to enable Customer to respond to requests by Data Subjects to exercise their rights. If B5 Secure receives such a request directly, it will, unless legally required to respond, advise the Data Subject to contact Customer.

8.Personal Data Breach

B5 Secure will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, and will provide information reasonably available to it and cooperate in Customer’s investigation and notification obligations.

9.Assistance

Taking into account the nature of Processing and the information available to it, B5 Secure will provide reasonable assistance to Customer with data-protection impact assessments and prior consultations with supervisory authorities.

10.International Transfers

Where B5 Secure’s Processing involves a transfer of Personal Data from the EEA, the United Kingdom, or Switzerland to a country without an adequacy decision, the SCCs are incorporated into this DPA by reference and apply, with the modules and options selected as appropriate to the parties’ roles, the UK International Data Transfer Addendum for UK transfers, and the Swiss amendments for Swiss transfers. Annexes I and II populate the corresponding annexes of the SCCs. In a conflict, the SCCs prevail over this DPA as to the transfers they govern.

11.Deletion or Return

On termination of the services, B5 Secure will, at Customer’s choice, delete or return Customer Personal Data it processes as a Processor, and delete existing copies unless retention is required by law.

12.Audits

B5 Secure will make available to Customer information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by Customer or its mandated auditor, subject to reasonable notice, confidentiality, frequency, and security conditions, and at Customer’s expense.

13.Liability; Precedence

Each party’s liability under this DPA is subject to the limitations and exclusions of liability in the Agreement. In the event of a conflict between this DPA and the Agreement regarding the Processing of Personal Data, this DPA controls; in the event of a conflict between this DPA and the SCCs, the SCCs control.

14.Term; General

This DPA takes effect on execution and continues for as long as B5 Secure processes Customer Personal Data as a Processor. It is governed by the law of the Agreement except where Applicable Data Protection Law or the SCCs require otherwise. Notices to B5 Secure: privacy@b5secure.com; PO Box 1410, Menlo Park, CA 94026-1410.

Annex I.Description of Processing

A. Parties. Data exporter: Customer (Controller). Data importer: B5 SECURE LLC (Processor). B. Description. Categories of Data Subjects: Customer’s authorized users and personnel who interact with B5 Secure support and license administration. Categories of Personal Data: name, business contact details, account and license identifiers, and support-communication content. Special categories: none intended. Frequency: continuous, as needed for the services. Nature and purpose: providing support, administering licenses and acceptances, and operating the services. Duration: the term of the Agreement plus legally required retention. C. Supervisory authority: the competent authority determined under the SCCs based on Customer’s establishment or representative.

Annex II.Technical and Organizational Measures

Measures include: access controls and least-privilege administration; encryption of data in transit and, where appropriate, at rest; secure development and change management; logging and monitoring; vulnerability and patch management; personnel confidentiality and security training; vendor risk management; and incident-response and business-continuity procedures. Measures are reviewed periodically and updated to reflect risk. Certification statuses are published on the B5 Secure Trust Center.

Annex III.Sub-processors

B5 Secure engages Sub-processors for hosting of its corporate systems, email and communications, analytics for its website, and the spreadsheet/records service used to log agreement acceptances. The current list, with the processing activity and location of each Sub-processor, is provided to Customer on request and maintained as part of this Annex III; B5 Secure provides advance notice of changes as described in Section 6.

Download PDF These terms are accepted by your access to and use of the B5 Secure website and materials.

Scroll to Top