Data Processing Addendum

Updated

January 11, 2022

This Data Processing Addendum (“Addendum”) forms part of the Terms of Service (“Terms”) between you (“Customer”) and Matter.

1. Subject Matter and Duration.

Subject Matter. This Addendum reflects the parties’ commitment to abide by Data Protection Laws concerning the Processing of Customer Personal Data in connection with Matter’s execution of the Terms. All capitalized terms that are not expressly defined in this Addendum will have the meanings given to them in the Terms.

2. Definitions.

For the purposes of this Addendum, the following terms and those defined within the body of this Addendum apply.

  1. Customer Personal Data means Customer Data that is Personal Data Processed by Matter on behalf of Customer.
  2. Data Protection Laws means all applicable data privacy, data protection, and cybersecurity laws, rules and regulations to which the Customer Personal Data are subject.
  3. Personal Data has the meaning assigned to the term “personal data” or “personal information” under applicable Data Protection Laws.
  4. Process or Processing means any operation or set of operations which is performed on Personal Data or sets of Personal Data.
  5. Security Incident(s) means the breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data attributable to Matter.
  6. Services means the services that Matter performs under the Terms.
  7. Subprocessor(s) means Matter’s authorized vendors and third-party service providers that Process Customer Personal Data.

3. Data Use and Processing.

  1. Documented Instructions. Matter shall Process Customer Personal Data to provide the Service in accordance with the Terms, this Addendum, and any instructions agreed upon by the parties.
  2. Authorization to Use Subprocessors. To the extent necessary to fulfill Matter’s contractual obligations under the Terms, Customer hereby authorizes Matter to engage Subprocessors.
  3. Confidentiality. Any person authorized to Process Customer Personal Data must contractually agree to maintain the confidentiality of such information or be under an appropriate statutory obligation of confidentiality.
  4. Sale of Customer Personal Data Prohibited. Matter shall not sell Customer Personal Data as the term "sell" is defined by the CCPA.

4. Information Security Program.

  1. Security Measures. Matter shall use commercially reasonable efforts to implement and maintain reasonable administrative, technical, and physical safeguards designed to protect Customer Personal Data.

5. Security Incidents.

  1. Notice. Upon becoming aware of a Security Incident, Matter agrees to provide written notice without undue delay and within the time frame required under Data Protection Laws to Customer.

6. Cross-Border Transfers of Customer Personal Data.

  1. Customer authorizes Matter and its Subprocessors to transfer Customer Personal Data across international borders, including from the European Economic Area, Switzerland, and/or the United Kingdom to the United States.

10. Processing Details.

  1. Subject Matter. The subject matter of the Processing is the Services pursuant to the Terms.
  2. Duration. The Processing will continue until the expiration or termination of the Terms.
  3. Categories of Data Subjects. Data subjects whose Customer Personal Data will be Processed pursuant to the Terms.
  4. Nature and Purpose of the Processing. The purpose of the Processing of Customer Personal Data by Matter is the performance of the Service.
  5. Types of Customer Personal Data. Customer Personal Data that is Processed pursuant to the Terms.

EXHIBIT A TO THE DATA PROCESSING ADDENDUM

Data Transfer Impact Assessment Questionnaire

This Exhibit A forms part of the Addendum. Capitalized terms not defined in this Exhibit A have the meaning set forth in the Addendum.

  1. What countries will Customer Personal Data that is transferred outside of the European Economic Area, Switzerland, and/or the United Kingdom be stored in or accessed from?
    Answer: United States of America.
  2. What are the categories of data subjects whose Customer Personal Data will be transferred outside of the European Economic Area, Switzerland, and/or the United Kingdom?
    Answer: As set forth in Section 10(c) of the Addendum.
  3. What are the categories of Customer Personal Data transferred outside of the European Economic Area, Switzerland, and/or the United Kingdom?
    Answer: As set forth in Section 10(e) of the Addendum.
  4. Will any Customer Personal Data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, genetic data, or biometric data for the purpose of uniquely identifying a natural person, data concerning health or a person’s sex life or sexual orientation, or data relating to criminal convictions and offences be transferred outside of the European Economic Area, Switzerland, and/or the United Kingdom?
    Answer: Not to Matter’s knowledge.
  5. What business sector is Matter involved in?
    Answer: Software.
  6. Broadly speaking, what are the services to be provided and the corresponding purposes for which Customer Personal Data is transferred outside of the European Economic Area, Switzerland, and/or the United Kingdom?
    Answer: Matter provides services for software/app development. Customer Personal Data is transferred outside of the European Economic Area, Switzerland, and/or the United Kingdom in order to provide the Service.
  7. What is the frequency of the transfer of Customer Personal Data outside of outside of the European Economic Area, Switzerland, and/or the United Kingdom?
    Answer: Customer Personal Data is transferred on a continuous basis by virtue of Customer’s use of the Service.
  8. When Customer Personal Data is transferred outside of the European Economic Area, Switzerland, and/or the United Kingdom to Matter, how is it transmitted to Matter?
    Answer: Matter encrypts your data aligning with industry-tested and accepted standards. We use TLS 1.2 to encrypt network traffic between users' browsers and the Matter’s platform. We also use AES-256 bit encryption to secure your database connection credentials and data stored at rest.
  9. What is the period for which the Customer Personal Data will be retained, or, if that is not possible, the criteria used to determine that period?
    Answer: Customer Personal Data will be retained in accordance with the Addendum.
  10. Please list the Subprocessors that will have access to Customer Personal Data that is transferred outside of the European Economic Area, Switzerland, and/or the United Kingdom:
    Answer: A current list of Matter’s Subprocessors can be found at: https://matterapp.com/legal/sub-processors.'