OBSIDIAN SECURITY, INC.
This Data Processing Agreement, including its Annexes and the Standard Contractual Clauses (the “DPA”), forms an integral part of the Obsidian Terms of Service entered into between the entity identified as the “Subscriber” (“Subscriber”) and Obsidian Security, Inc. or its Affiliate, each as named on the applicable Order Form (“Obsidian”) (the “Agreement”) and applies solely to the extent that Obsidian processes Subscriber Personal Data (defined below) in connection with the Services. This DPA is effective as of the date Subscriber accepts the Agreement and applies for the duration of Obsidian's processing of Subscriber Personal Data. By accepting the Agreement, Subscriber enters into this DPA on behalf of itself and, to the extent required under Applicable Data Protection Laws, on behalf of its Authorized Affiliates. All capitalized terms not defined herein shall have the meaning set forth in the Agreement. Except where otherwise indicated, the term “Subscriber” shall include Subscriber and its Authorized Affiliates.
ANNEX 1(A): LIST OF PARTIES
Data exporter
Name of the data exporter: The entity identified as the “Subscriber” in the Agreement and this DPA.
Contact person’s name, position, and contact details: The address and contact details associated with Subscriber's Obsidian account, or as otherwise specified in this DPA or the Agreement.
Activities relevant to the data transferred: The activities specified in Annex 1(B)below.
Signature and date: By acceptance of the Agreement and its effective date
Role (Controller/Processor): Controller (for Module 2) or Processor (for Module 3).
Data exporter
Name of the data importer: Obsidian Security, Inc. or the Obsidian Affiliate named on the applicable Order Form
Contact person’s name, position, and contact details: The person identified in the Documentation for a specific Service
Activities relevant to the data transferred: The activities specified in Annex 1.B below.
Signature and date: By acceptance of the Agreement and its effective date
Role (Controller/Processor): Processor or Subprocessor
ANNEX 1(B): DESCRIPTION OF THE PROCESSING / TRANSFER
Categories of data subjects whose personal data is transferred:
Name of the data importer: Obsidian Security, Inc. or the Obsidian Affiliate named on the applicable Order Form
Contact person’s name, position, and contact details: The person identified in the Documentation for a specific Service
Activities relevant to the data transferred: The activities specified in Annex 1.B below.
Signature and date: By acceptance of the Agreement and its effective date
Role (Controller/Processor): Processor or Subprocessor
Categories of personal data transferred:
Name of the data importer: Obsidian Security, Inc. or the Obsidian Affiliate named on the applicable Order Form
Contact person’s name, position, and contact details: The person identified in the Documentation for a specific Service
Activities relevant to the data transferred: The activities specified in Annex 1.B below.
Signature and date: By acceptance of the Agreement and its effective date
Role (Controller/Processor): Processor or Subprocessor
Sensitive data transferred (if appropriate)
N/A
Frequency of the Transfer
Continuous
Nature, subject matter, and duration of the processing:
Purpose(s) of the data transfer and further processing:
Providing the Services set out in the Agreement and any applicable Order Form or statement of work.
Period for which the personal data will be retained:
Obsidian will retain Subscriber Personal Data for the term of the Agreement and any period after the termination of expiry of the Agreement during which Obsidian processes Subscriber Personal Data in accordance with the Agreement.
ANNEX 1(B): DESCRIPTION OF THE PROCESSING / TRANSFER
Period for which the personal data will be retained:
The data exporter's competent supervisory authority will be determined in accordance with the EU GDPR.
Subprocessors
Subprocessor List
Obsidian’s list of subprocessors is available at trust.obsidiansecurity.com