Last Updated: June 16, 2025
This Data Protection Addendum ("Addendum") forms part of the Master License and Software Agreement, as updated from time to time, ("Agreement") for Lumivero Software and Services, which is the basis for the agreement between Lumivero, LLC or one of its Affiliates ("Lumivero") and Customer.
This Addendum shall apply to Personal Data that Lumivero or a Lumivero Affiliate processes in the course of providing the Cloud Services to Customer under the Agreement.
Customer enters into this Addendum on behalf of itself and, to the extent required under applicable Data Protection Laws, in the name and on behalf of its Customer Affiliates, if and to the extent Lumivero processes Personal Data as the Processor for which such Customer Affiliates qualify as the Controller.
1. DATA PROCESSING TERMS
1.1 Definitions
In this Addendum, unless the context otherwise requires, the following terms have the meaning set out below.
Applicable Laws means, to the extent binding on any party, all laws, rules and/or regulations applicable to the Agreement (as amended) or the activities contemplated thereunder, including, without limitation, any applicable Data Protection Laws;
Customer Affiliate means an entity that owns or controls, is owned or controlled by or is or under common control or ownership with Customer, where “control” is defined as the possession, directly or indirectly, of the power to direct or cause the direction of the management and policies of an entity, whether through ownership of voting securities, by contract or otherwise;
Customer Group Member means Customer or any Customer Affiliate;
Customer Personal Data means any Personal Data Processed by a Processor on behalf of a Customer Group Member pursuant to or in connection with the Agreement;
Data Protection Laws means all laws, regulations, binding legislative and regulatory requirements and codes of practice relating to data protection and the Processing of Personal Data, which apply to either party or the Services, which may include:
EEA means the European Economic Area;
EU GDPR means the EU General Data Protection Regulation 2016/679 of the European Parliament and of the Council of 27 April 2016;
GDPR means the EU GDPR and/or UK GDPR (as applicable);
Processor means any Lumivero Group Member which processes Customer Personal Data;
Lumivero Affiliate means an entity that owns or controls, is owned or controlled by or is under common control or ownership with Lumivero, LLC; and
Lumivero Group Member means Lumivero International, LLC or any Lumivero Affiliate.
Restricted Transfer means:
Services means the services and other activities to be supplied to or carried out by or on behalf of Lumivero for the relevant Customer Group Members pursuant to the Agreement;
Standard Contractual Clauses means the applicable clauses set out in the Annex to the European Commission Implementing Decision on standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council, and any new standard contractual clauses replacing or amending the existing standard contractual clauses approved for use by the European Commission from time to time;
Subprocessor means any person (including any third party and any Lumivero Affiliate, but excluding an employee of Lumivero) appointed by or on behalf of Lumivero to Process Customer Personal Data in connection with the Agreement;
UK means the United Kingdom;
UK Addendum means the international data transfer addendum to the Standard Contractual Clauses issued by the UK Information Commissioner’s Office under S119A(1) of the UK Data Protection Act 2018, and any new clauses replacing or amending the existing UK Addendum approved for use by the Information Commissioner’s Office from time to time;
UK GDPR means the UK version of the GDPR as it forms part of the law of each applicable jurisdiction of the United Kingdom pursuant to the European Union (Withdrawal) Act 2018;
The terms, "Controller", "Data Subject", "Personal Data", "Personal Data Breach", "Processing" and "Supervisory Authority" (or equivalent terms) shall have the meanings set out in, and will be interpreted in accordance with, such Data Protection Laws as are applicable from time to time.
2. INTERPRETATION
3. STATUS OF PARTIES
4. CUSTOMER OBLIGATIONS
5. PROCESSING OF CUSTOMER PERSONAL DATA
6. Lumivero AND Lumivero AFFILIATE PERSONNEL
The Processor shall take reasonable steps to ensure that any employee, agent or contractor of any of them who may have access to the Customer Personal Data is subject to confidentiality undertakings or professional or statutory obligations of confidentiality and only Processes the Customer Personal Data on instructions from Customer.
7. SECURITY
Lumivero shall, and shall where it is not the Processor, procure that the relevant Lumivero Affiliate implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk presented by Processing, in particular from accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Customer Personal Data transmitted, stored or otherwise Processed in accordance with Data Protection Laws, including, as appropriate, the measures referred to in Article 32(1) of the GDPR. The standard security measures that the Contracted Processor shall implement shall include those measures set out in the Standard Contractual Clauses..
8. SUBPROCESSING
9. INTERNATIONAL DATA TRANSFERS
In relation to Restricted Transfers Lumivero and Customer:
10. DATA SUBJECT RIGHTS
11. PERSONAL DATA BREACH
12. DATA PROTECTION IMPACT ASSESSMENT AND PRIOR CONSULTATION
The Processor shall provide reasonable assistance to Customer with any data protection impact assessments, and prior consultations with Supervising Authorities or other competent data privacy authorities, as required under Data Protection Law, in each case solely in relation to Processing of Customer Personal Data by, and taking into account the nature of the Processing and information available to, the Processor.
13. DELETION OR RETURN OF CUSTOMER PERSONAL DATA
14. AUDIT RIGHTS
15. GENERAL
Where a provision requires the Processor to assist Customer or a Customer Group Member with compliance with their obligations under Data Protection Laws, such assistance shall be provided at no additional cost where this can reasonably be accommodated within the standard provision of the Services. Otherwise, the associated costs shall be agreed between the parties in accordance with the change control or Addendum procedure applicable under the Agreement.
16. ORDER OF PRECEDENCE
With regard to the subject matter of this Addendum, in the event of inconsistencies between the provisions of this Addendum and any other agreements between the parties, including the Agreement and including (except where explicitly agreed otherwise in writing, signed on behalf of the parties) agreements entered into or purported to be entered into after the date of this Addendum, the provisions of this Addendum shall prevail.
Details of Processing of Customer Personal Data
This Schedule 1 includes certain details of the Processing of Customer Personal Data as required by Article 28(3) GDPR and the Standard Contractual Clauses.
1. List of parties
Data exporter (as the context requires):
Customer, whose contact details are as described in the Agreement and which will act as a Controller of Customer Personal Data; or
Lumivero, whose contact details are as described in the Agreement and which will act as a Controller and/or a Processor of Customer Personal Data, as the context requires.
Data importer (as the context requires):
Lumivero, whose contact details are as described in the Agreement and which will act as a Controller and/or a Processor of Customer Personal Data, as the context requires; or
Customer, whose contact details are as described in the Agreement and which will act as a Controller of Customer Personal Data.
2. Subject matter and duration of the Processing of Customer Personal Data
The subject matter of the Processing of the Customer Personal Data is set out in the Agreement. Processing of the Customer Personal Data by the Processor shall be for the term of the Agreement, provided that Personal Data shall not be Processed for longer than is necessary for the purpose for which it was collected or is being Processed (except where a statutory exception applies).
3. The nature and purpose of the Processing of Customer Personal Data
The Processing of Customer Personal Data is Lumivero's provision of the applicable services under the Agreement, which shall involve performance on behalf of the relevant Customer Group Member of the tasks and activities set out in the Agreement for the purpose of providing those Services.
4. The types of Customer Personal Data to be Processed
The Processor may Process any or all of the following types / categories of Personal Data, and any additional types of Customer Personal Data, as set out in the Agreement and as relevant in the context of the Services including:
5. The categories of Data Subject to whom the Customer Personal Data relates
The categories of Data Subjects includes any or all of the following individuals: Customer Group Member customers and clients, research participants, Customer Group Member advisers, consultants and other professional experts, Customer Group Member employees and staff, Customer Group Member Lumiveros and services providers, complainants and enquirers who contact Customer Group Members, and / or individuals captured by CCTV images, including staff, customers and clients, offenders and suspected offenders, members of the public and those inside, entering or in the immediate vicinity of the area under surveillance.
6. The obligations and rights of Customer and Customer Affiliates
The obligations and rights of Company and Company Affiliates are set out in the Agreement (as varied).
7. The frequency of Restricted Transfers (where applicable)
On a continuous basis as necessary to deliver the Services.
8. Transfers to (sub-)processors
For the purposes and to the entities described in the Agreement and this Addendum.
9. The competent supervisory authority for Restricted Transfers (where applicable)
As described in Clause 13 of the Standard Contractual Clauses and/or Clause 15(k) of the UK Addendum, as the case may be.
How can we help you? Contact us.