Lexicon

Data Processing Agreement

Type: AgreementDate: 15 January 2026draftv1.4Ref: OK:RP:20260115
Parties:
Supplier Pty Ltd ACN 001 002 987Supplier
Tiny Company Pty Ltd ACN 123 456 987Merchant

Background

1

The MerchantMerchantTiny Company Pty Ltd and SupplierSupplierSupplier Pty Ltd are parties to an agreement for the provision of ServicesServicesmeans the services and other activities to be supplied to or carried out by or on behalf of Supplier for Merchant Group Members pursuant to the Principal AgreementDefined in clause 1.1(r) (the Principal Agreement).

2

In the course of performing its obligations under the Principal Agreement, SupplierSupplierSupplier Pty Ltd will Process Merchant Personal DataMerchant Personal Datameans any Personal Data Processed by a Contracted Processor on behalf of a Merchant Group Member pursuant to or in connection with the Principal AgreementDefined in clause 1.1(l) on behalf of the MerchantMerchantTiny Company Pty Ltd as a Processor.

3

The parties have agreed to enter into this Agreement in order to:

3.1

ensure that the ProcessingProcessingmeans any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring,…Defined in clause 1.1(n) of Merchant Personal DataMerchant Personal Datameans any Personal Data Processed by a Contracted Processor on behalf of a Merchant Group Member pursuant to or in connection with the Principal AgreementDefined in clause 1.1(l) by SupplierSupplierSupplier Pty Ltd and its SubprocessorsSubprocessormeans any person (including any third party and any Supplier Affiliate, but excluding an employee of Supplier or any of its sub-contractors) appointed by or on behalf of Supplier or any Supplier…Defined in clause 1.1(t) is carried out in compliance with all Applicable LawsApplicable Lawsmeans : (i) European Union or Member State laws with respect to any Merchant Personal Data in respect of which any Merchant Group Member is subject to EU Data Protection Laws; and (ii) the UK Data…Defined in clause 1.1(a), including the GDPRGDPRmeans EU General Data Protection Regulation 2016/679Defined in clause 1.1(g), UK Data Protection LawsUK Data Protection Lawsmeans the UK Data Protection Act 2018, the Digital Markets, Competition and Consumers Act 2024 (UK) and the UK-GDPRDefined in clause 1.1(u), US Data Protection LawsUS Data Protection Lawsmeans the CCPA, the Colorado Privacy Act, Colorado Rev. Stat. 6-1-1301 et seq. (the CPA); the Connecticut Act Concerning Personal Data Protection and Online Monitoring, Conn. PA 22-15 § 1 et seq.…Defined in clause 1.1(w), and the data protection and privacy laws of Australia, Canada, and New Zealand;

3.2

set out the parties' respective rights and obligations in relation to the ProcessingProcessingmeans any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring,…Defined in clause 1.1(n) of Merchant Personal DataMerchant Personal Datameans any Personal Data Processed by a Contracted Processor on behalf of a Merchant Group Member pursuant to or in connection with the Principal AgreementDefined in clause 1.1(l); and

3.3

satisfy the requirements of Article 28(3) of the GDPRGDPRmeans EU General Data Protection Regulation 2016/679Defined in clause 1.1(g) and equivalent provisions under other applicable Data Protection LawsData Protection Lawsmeans to the extent applicable: (i) the EU Data Protection Laws; (ii) the UK Data Protection Laws; (iii) the US Data Protection Laws; (iv) any data protection or privacy laws of: (A) The Commonwealth…Defined in clause 1.1(e) for a written agreement between a ControllerControllerDefined in clause 1.3 and a Processor.

4

This Agreement is supplemental to, and forms part of, the Principal Agreement. In the event of any conflict between this Agreement and the Principal Agreement in relation to the ProcessingProcessingmeans any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring,…Defined in clause 1.1(n) of Merchant Personal DataMerchant Personal Datameans any Personal Data Processed by a Contracted Processor on behalf of a Merchant Group Member pursuant to or in connection with the Principal AgreementDefined in clause 1.1(l), this Agreement shall prevail.

Agreement

1.

Definitions

1.1

In this Agreement, the following terms shall have the meanings set out below and cognate terms shall be construed accordingly:

(a)

Applicable LawsApplicable Lawsmeans : (i) European Union or Member State laws with respect to any Merchant Personal Data in respect of which any Merchant Group Member is subject to EU Data Protection Laws; and (ii) the UK Data…Defined in clause 1.1(a) means:

(i)

European Union or Member StateMember StateDefined in clause 1.3 laws with respect to any Merchant Personal DataMerchant Personal Datameans any Personal Data Processed by a Contracted Processor on behalf of a Merchant Group Member pursuant to or in connection with the Principal AgreementDefined in clause 1.1(l) in respect of which any Merchant Group MemberMerchant Group Membermeans Merchant or any Merchant AffiliateDefined in clause 1.1(k) is subject to EU Data Protection LawsEU Data Protection Lawsmeans the Privacy and Electronic Communication (EC Directive) Regulations 2003 and the EU Directive 95/46/EC, as transposed into domestic legislation of each Member State and as amended, replaced or…Defined in clause 1.1(f); and

(ii)

the UK Data Protection LawsUK Data Protection Lawsmeans the UK Data Protection Act 2018, the Digital Markets, Competition and Consumers Act 2024 (UK) and the UK-GDPRDefined in clause 1.1(u) in respect of which any Merchant Group MemberMerchant Group Membermeans Merchant or any Merchant AffiliateDefined in clause 1.1(k) is subject to the laws of the United Kingdom of Great Britain and Northern Ireland;

(iii)

the CCPACCPAmeans the California Consumer Privacy Act of 2018, AB 375 as amended, including by the California Privacy Rights Act, and its accompanying regulationsDefined in clause 1.1(b) in respect of which any Merchant Group MemberMerchant Group Membermeans Merchant or any Merchant AffiliateDefined in clause 1.1(k) is subject to the laws of the State of California, United States of America; and

(iv)

any other Data Protection LawsData Protection Lawsmeans to the extent applicable: (i) the EU Data Protection Laws; (ii) the UK Data Protection Laws; (iii) the US Data Protection Laws; (iv) any data protection or privacy laws of: (A) The Commonwealth…Defined in clause 1.1(e) that any Merchant Group MemberMerchant Group Membermeans Merchant or any Merchant AffiliateDefined in clause 1.1(k) is subject to.

(b)

CCPACCPAmeans the California Consumer Privacy Act of 2018, AB 375 as amended, including by the California Privacy Rights Act, and its accompanying regulationsDefined in clause 1.1(b) means the California Consumer Privacy Act of 2018, AB 375 as amended, including by the California Privacy Rights Act, and its accompanying regulations.

(c)

Contracted ProcessorContracted Processormeans Supplier or a SubprocessorDefined in clause 1.1(c) means SupplierSupplierSupplier Pty Ltd or a SubprocessorSubprocessormeans any person (including any third party and any Supplier Affiliate, but excluding an employee of Supplier or any of its sub-contractors) appointed by or on behalf of Supplier or any Supplier…Defined in clause 1.1(t).

(d)

Data SubjectData Subjectmeans an Identifiable Natural Person about whom the Merchant or Supplier holds Personal Data and who is subject to the Data Protection LawsDefined in clause 1.1(d) means an Identifiable Natural PersonIdentifiable Natural Personmeans a person who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or…Defined in clause 1.1(i) about whom the MerchantMerchantTiny Company Pty Ltd or SupplierSupplierSupplier Pty Ltd holds Personal DataPersonal Datameans any information relating to an Identifiable Natural Person and includes the terms 'personal data' and 'personal information' under any applicable Data Protection LawsDefined in clause 1.1(o) and who is subject to the Data Protection LawsData Protection Lawsmeans to the extent applicable: (i) the EU Data Protection Laws; (ii) the UK Data Protection Laws; (iii) the US Data Protection Laws; (iv) any data protection or privacy laws of: (A) The Commonwealth…Defined in clause 1.1(e).

(e)

Data Protection LawsData Protection Lawsmeans to the extent applicable: (i) the EU Data Protection Laws; (ii) the UK Data Protection Laws; (iii) the US Data Protection Laws; (iv) any data protection or privacy laws of: (A) The Commonwealth…Defined in clause 1.1(e) means to the extent applicable:

(i)

the EU Data Protection LawsEU Data Protection Lawsmeans the Privacy and Electronic Communication (EC Directive) Regulations 2003 and the EU Directive 95/46/EC, as transposed into domestic legislation of each Member State and as amended, replaced or…Defined in clause 1.1(f);

(ii)

the UK Data Protection LawsUK Data Protection Lawsmeans the UK Data Protection Act 2018, the Digital Markets, Competition and Consumers Act 2024 (UK) and the UK-GDPRDefined in clause 1.1(u);

(iii)

the US Data Protection LawsUS Data Protection Lawsmeans the CCPA, the Colorado Privacy Act, Colorado Rev. Stat. 6-1-1301 et seq. (the CPA); the Connecticut Act Concerning Personal Data Protection and Online Monitoring, Conn. PA 22-15 § 1 et seq.…Defined in clause 1.1(w);

(iv)

any data protection or privacy laws of:

(A)

The Commonwealth of Australia, or any state therein;

(I)

This is a level 6 test.

(B)

Canada, or any province therein; and

(C)

New Zealand.

(f)

EU Data Protection LawsEU Data Protection Lawsmeans the Privacy and Electronic Communication (EC Directive) Regulations 2003 and the EU Directive 95/46/EC, as transposed into domestic legislation of each Member State and as amended, replaced or…Defined in clause 1.1(f) means the Privacy and Electronic Communication (EC Directive) Regulations 2003 and the EU Directive 95/46/EC, as transposed into domestic legislation of each Member StateMember StateDefined in clause 1.3 and as amended, replaced or superseded from time to time, including by the GDPRGDPRmeans EU General Data Protection Regulation 2016/679Defined in clause 1.1(g) and laws implementing or supplementing the GDPRGDPRmeans EU General Data Protection Regulation 2016/679Defined in clause 1.1(g).

(g)

GDPRGDPRmeans EU General Data Protection Regulation 2016/679Defined in clause 1.1(g) means EU General Data Protection Regulation 2016/679.

(h)

GDPR ZoneGDPR Zonemeans : (i) The European Economic Area with respect to any Merchant Personal Data in respect of which any Merchant Group Member is subject to EU Data Protection Laws; or (ii) The United Kingdom of…Defined in clause 1.1(h) means:

(i)

The European Economic Area with respect to any Merchant Personal DataMerchant Personal Datameans any Personal Data Processed by a Contracted Processor on behalf of a Merchant Group Member pursuant to or in connection with the Principal AgreementDefined in clause 1.1(l) in respect of which any Merchant Group MemberMerchant Group Membermeans Merchant or any Merchant AffiliateDefined in clause 1.1(k) is subject to EU Data Protection LawsEU Data Protection Lawsmeans the Privacy and Electronic Communication (EC Directive) Regulations 2003 and the EU Directive 95/46/EC, as transposed into domestic legislation of each Member State and as amended, replaced or…Defined in clause 1.1(f); or

(ii)

The United Kingdom of Great Britain and Northern Ireland in respect of which any Merchant Group MemberMerchant Group Membermeans Merchant or any Merchant AffiliateDefined in clause 1.1(k) is subject to the laws of the United Kingdom of Great Britain and Northern Ireland.

(i)

Identifiable Natural PersonIdentifiable Natural Personmeans a person who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or…Defined in clause 1.1(i) means a person who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.

(j)

Merchant AffiliateMerchant Affiliatemeans an entity that owns or controls, is owned or controlled by or is or under common control or ownership with Merchant, where control is defined as the possession, directly or indirectly, of the…Defined in clause 1.1(j) means an entity that owns or controls, is owned or controlled by or is or under common control or ownership with MerchantMerchantTiny Company Pty Ltd, where control is defined as the possession, directly or indirectly, of the power to direct or cause the direction of the management and policies of an entity, whether through ownership of voting securities, by contract or otherwise.

(k)

Merchant Group MemberMerchant Group Membermeans Merchant or any Merchant AffiliateDefined in clause 1.1(k) means MerchantMerchantTiny Company Pty Ltd or any Merchant AffiliateMerchant Affiliatemeans an entity that owns or controls, is owned or controlled by or is or under common control or ownership with Merchant, where control is defined as the possession, directly or indirectly, of the…Defined in clause 1.1(j).

(l)

Merchant Personal DataMerchant Personal Datameans any Personal Data Processed by a Contracted Processor on behalf of a Merchant Group Member pursuant to or in connection with the Principal AgreementDefined in clause 1.1(l) means any Personal DataPersonal Datameans any information relating to an Identifiable Natural Person and includes the terms 'personal data' and 'personal information' under any applicable Data Protection LawsDefined in clause 1.1(o) Processed by a Contracted ProcessorContracted Processormeans Supplier or a SubprocessorDefined in clause 1.1(c) on behalf of a Merchant Group MemberMerchant Group Membermeans Merchant or any Merchant AffiliateDefined in clause 1.1(k) pursuant to or in connection with the Principal Agreement.

(m)

Supplier AffiliateSupplier Affiliatemeans an entity that owns or controls, is owned or controlled by or is or under common control or ownership with Supplier, where control is defined as the possession, directly or indirectly, of the…Defined in clause 1.1(m) means an entity that owns or controls, is owned or controlled by or is or under common control or ownership with SupplierSupplierSupplier Pty Ltd, where control is defined as the possession, directly or indirectly, of the power to direct or cause the direction of the management and policies of an entity, whether through ownership of voting securities, by contract or otherwise.

(n)

ProcessingProcessingmeans any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring,…Defined in clause 1.1(n) means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.

(o)

Personal DataPersonal Datameans any information relating to an Identifiable Natural Person and includes the terms 'personal data' and 'personal information' under any applicable Data Protection LawsDefined in clause 1.1(o) means any information relating to an Identifiable Natural PersonIdentifiable Natural Personmeans a person who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or…Defined in clause 1.1(i) and includesincludeDefined in clause 1.4 the terms 'personal data' and 'personal information' under any applicable Data Protection LawsData Protection Lawsmeans to the extent applicable: (i) the EU Data Protection Laws; (ii) the UK Data Protection Laws; (iii) the US Data Protection Laws; (iv) any data protection or privacy laws of: (A) The Commonwealth…Defined in clause 1.1(e).

(p)

Objection PeriodObjection Period (schedule)has the meaning given by the ScheduleDefined in clause 1.1(p) has the meaning given by the Schedule.

(q)

Personal Data BreachPersonal Data Breachmeans a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processedDefined in clause 1.1(q) means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed.

(r)

ServicesServicesmeans the services and other activities to be supplied to or carried out by or on behalf of Supplier for Merchant Group Members pursuant to the Principal AgreementDefined in clause 1.1(r) means the services and other activities to be supplied to or carried out by or on behalf of SupplierSupplierSupplier Pty Ltd for Merchant Group MembersMerchant Group Membermeans Merchant or any Merchant AffiliateDefined in clause 1.1(k) pursuant to the Principal Agreement.

(s)

Standard Contractual ClausesStandard Contractual Clausesmeans : (i) the European Commission's Standard Contractual Clauses for the transfer of personal data from the European Union to processors established in third countries (controller-to-processor…Defined in clause 1.1(s) means:

(i)

the European CommissionCommissionDefined in clause 1.3's Standard Contractual ClausesStandard Contractual Clausesmeans : (i) the European Commission's Standard Contractual Clauses for the transfer of personal data from the European Union to processors established in third countries (controller-to-processor…Defined in clause 1.1(s) for the transfer of personal data from the European Union to processors established in third countries (controller-to-processor transfers), as set out in European CommissionCommissionDefined in clause 1.3 Decision 2021/914/EU under Module Two (transfer controller to processor); and

(ii)

includesincludeDefined in clause 1.4, where any Merchant Group MemberMerchant Group Membermeans Merchant or any Merchant AffiliateDefined in clause 1.1(k) is subject to the laws of the United Kingdom of Great Britain and Northern Ireland, the International Data Transfer Addendum issued by the United Kingdom Information Commissioner under section 119(A)(1) of the Data Protection Act 2018.

(t)

SubprocessorSubprocessormeans any person (including any third party and any Supplier Affiliate, but excluding an employee of Supplier or any of its sub-contractors) appointed by or on behalf of Supplier or any Supplier…Defined in clause 1.1(t) means any person (including any third party and any Supplier AffiliateSupplier Affiliatemeans an entity that owns or controls, is owned or controlled by or is or under common control or ownership with Supplier, where control is defined as the possession, directly or indirectly, of the…Defined in clause 1.1(m), but excluding an employee of SupplierSupplierSupplier Pty Ltd or any of its sub-contractors) appointed by or on behalf of SupplierSupplierSupplier Pty Ltd or any Supplier AffiliateSupplier Affiliatemeans an entity that owns or controls, is owned or controlled by or is or under common control or ownership with Supplier, where control is defined as the possession, directly or indirectly, of the…Defined in clause 1.1(m) to Process Personal DataPersonal Datameans any information relating to an Identifiable Natural Person and includes the terms 'personal data' and 'personal information' under any applicable Data Protection LawsDefined in clause 1.1(o) on behalf of any Merchant Group MemberMerchant Group Membermeans Merchant or any Merchant AffiliateDefined in clause 1.1(k) in connection with the Principal Agreement.

(u)

UK Data Protection LawsUK Data Protection Lawsmeans the UK Data Protection Act 2018, the Digital Markets, Competition and Consumers Act 2024 (UK) and the UK-GDPRDefined in clause 1.1(u) means the UK Data Protection Act 2018, the Digital Markets, Competition and Consumers Act 2024 (UK) and the UK-GDPRUK-GDPRmeans the GDPR as amended by the Data Protection, Privacy and Electronic Communications (Amendments etc) (EU Exit) Regulations 2019 (SI 2019/419)Defined in clause 1.1(v).

(v)

UK-GDPRUK-GDPRmeans the GDPR as amended by the Data Protection, Privacy and Electronic Communications (Amendments etc) (EU Exit) Regulations 2019 (SI 2019/419)Defined in clause 1.1(v) means the GDPRGDPRmeans EU General Data Protection Regulation 2016/679Defined in clause 1.1(g) as amended by the Data Protection, Privacy and Electronic Communications (Amendments etc) (EU Exit) Regulations 2019 (SI 2019/419).

(w)

US Data Protection LawsUS Data Protection Lawsmeans the CCPA, the Colorado Privacy Act, Colorado Rev. Stat. 6-1-1301 et seq. (the CPA); the Connecticut Act Concerning Personal Data Protection and Online Monitoring, Conn. PA 22-15 § 1 et seq.…Defined in clause 1.1(w) means the CCPACCPAmeans the California Consumer Privacy Act of 2018, AB 375 as amended, including by the California Privacy Rights Act, and its accompanying regulationsDefined in clause 1.1(b), the Colorado Privacy Act, Colorado Rev. Stat. 6-1-1301 et seq. (the CPACPA (inline)Defined in clause 1.1(w)); the Connecticut Act Concerning Personal DataPersonal Datameans any information relating to an Identifiable Natural Person and includes the terms 'personal data' and 'personal information' under any applicable Data Protection LawsDefined in clause 1.1(o) Protection and Online Monitoring, Conn. PA 22-15 § 1 et seq. (the PDPOMPDPOM (inline)Defined in clause 1.1(w)); Iowa Consumer Data Protection Act, S.J. 708 (the ICDPAICDPA (inline)Defined in clause 1.1(w)); the Indiana Consumer Data Protection Act, S.B. 5 (the INCDPAINCDPA (inline)Defined in clause 1.1(w)); the Montana Consumer Data Privacy Act, S.B. 384 (the MCDPAMCDPA (inline)Defined in clause 1.1(w)); the Tennessee Information Protection Act, H.B. 1181 (the TIPATIPA (inline)Defined in clause 1.1(w)); the Utah Consumer Privacy Act, Utah Code 13-61-101 et seq. (the UCPAUCPA (inline)Defined in clause 1.1(w)); the Virginia Consumer Data Protection Act, Code of Virginia title 59.1, Chapter 52 (the VCDPAVCDPA (inline)Defined in clause 1.1(w)); the Fair Credit Reporting Act, 15 U.S.C. § 1681 et seq.; the Gramm-Leach-Bliley Act, 15 U.S.C. § 6801 et seq.; the Children's Online Privacy Protection Act, 15 U.S.C. § 6501 et seq.; Section 5 of the FTC Act, 15 U.S.C. § 45 and any applicable guidance issued by the U.S. Federal Trade CommissionCommissionDefined in clause 1.3, and any data protection or privacy laws of the United States of America and any states therein.

1.2

The terms used in this Agreement shall have the meanings set forth in this Agreement, and their cognate terms shall be construed accordingly. Capitalised terms not otherwise defined herein shall have the meaning given to them in the Principal Agreement. Except as modified below, the terms of the Principal Agreement shall remain in full force and effect.

1.3

The terms CommissionCommissionDefined in clause 1.3, ControllerControllerDefined in clause 1.3, Member StateMember StateDefined in clause 1.3, and Supervisory AuthoritySupervisory AuthorityDefined in clause 1.3 shall have the same meaning as in the GDPRGDPRmeans EU General Data Protection Regulation 2016/679Defined in clause 1.1(g) or UK-GDPRUK-GDPRmeans the GDPR as amended by the Data Protection, Privacy and Electronic Communications (Amendments etc) (EU Exit) Regulations 2019 (SI 2019/419)Defined in clause 1.1(v) as context requires, and their cognate terms shall be construed accordingly.

1.4

The word includeincludeDefined in clause 1.4 shall be construed to mean includeincludeDefined in clause 1.4 without limitation, and cognate terms shall be construed accordingly.

2.

Authority

2.1

SupplierSupplierSupplier Pty Ltd warrants and represents that, before any Supplier AffiliateSupplier Affiliatemeans an entity that owns or controls, is owned or controlled by or is or under common control or ownership with Supplier, where control is defined as the possession, directly or indirectly, of the…Defined in clause 1.1(m) Processes any Merchant Personal DataMerchant Personal Datameans any Personal Data Processed by a Contracted Processor on behalf of a Merchant Group Member pursuant to or in connection with the Principal AgreementDefined in clause 1.1(l) on behalf of any Merchant Group MemberMerchant Group Membermeans Merchant or any Merchant AffiliateDefined in clause 1.1(k), SupplierSupplierSupplier Pty Ltd's entry into this Agreement as agent for and on behalf of that Supplier AffiliateSupplier Affiliatemeans an entity that owns or controls, is owned or controlled by or is or under common control or ownership with Supplier, where control is defined as the possession, directly or indirectly, of the…Defined in clause 1.1(m) will have been duly and effectively authorised (or subsequently ratified) by that Supplier AffiliateSupplier Affiliatemeans an entity that owns or controls, is owned or controlled by or is or under common control or ownership with Supplier, where control is defined as the possession, directly or indirectly, of the…Defined in clause 1.1(m).

3.

ProcessingProcessingmeans any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring,…Defined in clause 1.1(n) of Merchant Personal DataMerchant Personal Datameans any Personal Data Processed by a Contracted Processor on behalf of a Merchant Group Member pursuant to or in connection with the Principal AgreementDefined in clause 1.1(l)

3.1

SupplierSupplierSupplier Pty Ltd is a Processor of Personal DataPersonal Datameans any information relating to an Identifiable Natural Person and includes the terms 'personal data' and 'personal information' under any applicable Data Protection LawsDefined in clause 1.1(o) on behalf of the MerchantMerchantTiny Company Pty Ltd.

3.2

SupplierSupplierSupplier Pty Ltd and each Supplier AffiliateSupplier Affiliatemeans an entity that owns or controls, is owned or controlled by or is or under common control or ownership with Supplier, where control is defined as the possession, directly or indirectly, of the…Defined in clause 1.1(m) shall:

(a)

comply with all applicable Applicable LawsApplicable Lawsmeans : (i) European Union or Member State laws with respect to any Merchant Personal Data in respect of which any Merchant Group Member is subject to EU Data Protection Laws; and (ii) the UK Data…Defined in clause 1.1(a) in the ProcessingProcessingmeans any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring,…Defined in clause 1.1(n) of Merchant Personal DataMerchant Personal Datameans any Personal Data Processed by a Contracted Processor on behalf of a Merchant Group Member pursuant to or in connection with the Principal AgreementDefined in clause 1.1(l); and

(b)

not Process Merchant Personal DataMerchant Personal Datameans any Personal Data Processed by a Contracted Processor on behalf of a Merchant Group Member pursuant to or in connection with the Principal AgreementDefined in clause 1.1(l) other than on the relevant Merchant Group MemberMerchant Group Membermeans Merchant or any Merchant AffiliateDefined in clause 1.1(k)'s documented instructions unless ProcessingProcessingmeans any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring,…Defined in clause 1.1(n) is required by Applicable LawsApplicable Lawsmeans : (i) European Union or Member State laws with respect to any Merchant Personal Data in respect of which any Merchant Group Member is subject to EU Data Protection Laws; and (ii) the UK Data…Defined in clause 1.1(a) to which the relevant Contracted ProcessorContracted Processormeans Supplier or a SubprocessorDefined in clause 1.1(c) is subject, in which case SupplierSupplierSupplier Pty Ltd or the relevant Supplier AffiliateSupplier Affiliatemeans an entity that owns or controls, is owned or controlled by or is or under common control or ownership with Supplier, where control is defined as the possession, directly or indirectly, of the…Defined in clause 1.1(m) shall to the extent permitted by Applicable LawsApplicable Lawsmeans : (i) European Union or Member State laws with respect to any Merchant Personal Data in respect of which any Merchant Group Member is subject to EU Data Protection Laws; and (ii) the UK Data…Defined in clause 1.1(a) inform the relevant Merchant Group MemberMerchant Group Membermeans Merchant or any Merchant AffiliateDefined in clause 1.1(k) of that legal requirement before the relevant ProcessingProcessingmeans any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring,…Defined in clause 1.1(n) of that Personal DataPersonal Datameans any information relating to an Identifiable Natural Person and includes the terms 'personal data' and 'personal information' under any applicable Data Protection LawsDefined in clause 1.1(o).

3.3

Each Merchant Group MemberMerchant Group Membermeans Merchant or any Merchant AffiliateDefined in clause 1.1(k):

(a)

instructs SupplierSupplierSupplier Pty Ltd and each Supplier AffiliateSupplier Affiliatemeans an entity that owns or controls, is owned or controlled by or is or under common control or ownership with Supplier, where control is defined as the possession, directly or indirectly, of the…Defined in clause 1.1(m) (and authorises SupplierSupplierSupplier Pty Ltd and each Supplier AffiliateSupplier Affiliatemeans an entity that owns or controls, is owned or controlled by or is or under common control or ownership with Supplier, where control is defined as the possession, directly or indirectly, of the…Defined in clause 1.1(m) to instruct each SubprocessorSubprocessormeans any person (including any third party and any Supplier Affiliate, but excluding an employee of Supplier or any of its sub-contractors) appointed by or on behalf of Supplier or any Supplier…Defined in clause 1.1(t)) to:

(i)

Process Merchant Personal DataMerchant Personal Datameans any Personal Data Processed by a Contracted Processor on behalf of a Merchant Group Member pursuant to or in connection with the Principal AgreementDefined in clause 1.1(l); and

(ii)

in particular, transfer Merchant Personal DataMerchant Personal Datameans any Personal Data Processed by a Contracted Processor on behalf of a Merchant Group Member pursuant to or in connection with the Principal AgreementDefined in clause 1.1(l) to any country or territory,

as reasonably necessary for the provision of the ServicesServicesmeans the services and other activities to be supplied to or carried out by or on behalf of Supplier for Merchant Group Members pursuant to the Principal AgreementDefined in clause 1.1(r) and consistent with the Principal Agreement; and

(a)

warrants and represents that it is and will at all relevant times remain duly and effectively authorised to give the instruction set out in clause 3 on behalf of each relevant Merchant AffiliateMerchant Affiliatemeans an entity that owns or controls, is owned or controlled by or is or under common control or ownership with Merchant, where control is defined as the possession, directly or indirectly, of the…Defined in clause 1.1(j).

4.

SupplierSupplierSupplier Pty Ltd and Supplier AffiliateSupplier Affiliatemeans an entity that owns or controls, is owned or controlled by or is or under common control or ownership with Supplier, where control is defined as the possession, directly or indirectly, of the…Defined in clause 1.1(m) Personnel

4.1

SupplierSupplierSupplier Pty Ltd and each Supplier AffiliateSupplier Affiliatemeans an entity that owns or controls, is owned or controlled by or is or under common control or ownership with Supplier, where control is defined as the possession, directly or indirectly, of the…Defined in clause 1.1(m) shall take reasonable steps to ensure that with respect to any Merchant Personal DataMerchant Personal Datameans any Personal Data Processed by a Contracted Processor on behalf of a Merchant Group Member pursuant to or in connection with the Principal AgreementDefined in clause 1.1(l), access is strictly limited to those employees, agents or contractors of SupplierSupplierSupplier Pty Ltd, or any Contracted ProcessorContracted Processormeans Supplier or a SubprocessorDefined in clause 1.1(c), who need to know or access the relevant Merchant Personal DataMerchant Personal Datameans any Personal Data Processed by a Contracted Processor on behalf of a Merchant Group Member pursuant to or in connection with the Principal AgreementDefined in clause 1.1(l), as strictly necessary for the purposes of the Principal Agreement, and to comply with Applicable LawsApplicable Lawsmeans : (i) European Union or Member State laws with respect to any Merchant Personal Data in respect of which any Merchant Group Member is subject to EU Data Protection Laws; and (ii) the UK Data…Defined in clause 1.1(a) in the context of that individual's duties to the Contracted ProcessorContracted Processormeans Supplier or a SubprocessorDefined in clause 1.1(c), ensuring that all such individuals are subject to confidentiality undertakings or professional or statutory obligations of confidentiality.

5.

Security

5.1

Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of ProcessingProcessingmeans any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring,…Defined in clause 1.1(n) as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, SupplierSupplierSupplier Pty Ltd and each Supplier AffiliateSupplier Affiliatemeans an entity that owns or controls, is owned or controlled by or is or under common control or ownership with Supplier, where control is defined as the possession, directly or indirectly, of the…Defined in clause 1.1(m) shall in relation to the Merchant Personal DataMerchant Personal Datameans any Personal Data Processed by a Contracted Processor on behalf of a Merchant Group Member pursuant to or in connection with the Principal AgreementDefined in clause 1.1(l) implement appropriate technical and organizational measures to ensure a level of security appropriate to that risk, including, as appropriate:

(a)

the pseudonymisation and encryption of personal data;

(b)

the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services;

(c)

the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident; and

(d)

a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures for ensuring the security of the processing.

5.2

In assessing the appropriate level of security, SupplierSupplierSupplier Pty Ltd and each Supplier AffiliateSupplier Affiliatemeans an entity that owns or controls, is owned or controlled by or is or under common control or ownership with Supplier, where control is defined as the possession, directly or indirectly, of the…Defined in clause 1.1(m) shall take account of the risks that are presented by ProcessingProcessingmeans any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring,…Defined in clause 1.1(n), in particular from a Personal Data BreachPersonal Data Breachmeans a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processedDefined in clause 1.1(q).

6.

Subprocessing

6.1

Each Merchant Group MemberMerchant Group Membermeans Merchant or any Merchant AffiliateDefined in clause 1.1(k) authorises SupplierSupplierSupplier Pty Ltd and each Supplier AffiliateSupplier Affiliatemeans an entity that owns or controls, is owned or controlled by or is or under common control or ownership with Supplier, where control is defined as the possession, directly or indirectly, of the…Defined in clause 1.1(m) to appoint (and permit each SubprocessorSubprocessormeans any person (including any third party and any Supplier Affiliate, but excluding an employee of Supplier or any of its sub-contractors) appointed by or on behalf of Supplier or any Supplier…Defined in clause 1.1(t) appointed in accordance with clause 6 to appoint) SubprocessorsSubprocessormeans any person (including any third party and any Supplier Affiliate, but excluding an employee of Supplier or any of its sub-contractors) appointed by or on behalf of Supplier or any Supplier…Defined in clause 1.1(t) in accordance with clause 6 and any restrictions in the Principal Agreement.

6.2

SupplierSupplierSupplier Pty Ltd and each Supplier AffiliateSupplier Affiliatemeans an entity that owns or controls, is owned or controlled by or is or under common control or ownership with Supplier, where control is defined as the possession, directly or indirectly, of the…Defined in clause 1.1(m) may continue to use those SubprocessorsSubprocessormeans any person (including any third party and any Supplier Affiliate, but excluding an employee of Supplier or any of its sub-contractors) appointed by or on behalf of Supplier or any Supplier…Defined in clause 1.1(t) already engaged by SupplierSupplierSupplier Pty Ltd or any Supplier AffiliateSupplier Affiliatemeans an entity that owns or controls, is owned or controlled by or is or under common control or ownership with Supplier, where control is defined as the possession, directly or indirectly, of the…Defined in clause 1.1(m) as at the date of this Agreement, subject to SupplierSupplierSupplier Pty Ltd and each Supplier AffiliateSupplier Affiliatemeans an entity that owns or controls, is owned or controlled by or is or under common control or ownership with Supplier, where control is defined as the possession, directly or indirectly, of the…Defined in clause 1.1(m) in each case as soon as practicable meeting the obligations set out in clause 3.2(b).

6.3

SupplierSupplierSupplier Pty Ltd shall give MerchantMerchantTiny Company Pty Ltd prior written notice of the appointment of any new SubprocessorSubprocessormeans any person (including any third party and any Supplier Affiliate, but excluding an employee of Supplier or any of its sub-contractors) appointed by or on behalf of Supplier or any Supplier…Defined in clause 1.1(t), including full details of the ProcessingProcessingmeans any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring,…Defined in clause 1.1(n) to be undertaken by the SubprocessorSubprocessormeans any person (including any third party and any Supplier Affiliate, but excluding an employee of Supplier or any of its sub-contractors) appointed by or on behalf of Supplier or any Supplier…Defined in clause 1.1(t). If, within the Objection PeriodObjection Period (schedule)has the meaning given by the ScheduleDefined in clause 1.1(p) of receipt of that notice, MerchantMerchantTiny Company Pty Ltd notifies SupplierSupplierSupplier Pty Ltd in writing of any objections (on reasonable grounds) to the proposed appointment.

6.4

Neither SupplierSupplierSupplier Pty Ltd nor any Supplier AffiliateSupplier Affiliatemeans an entity that owns or controls, is owned or controlled by or is or under common control or ownership with Supplier, where control is defined as the possession, directly or indirectly, of the…Defined in clause 1.1(m) shall appoint (or disclose any Merchant Personal DataMerchant Personal Datameans any Personal Data Processed by a Contracted Processor on behalf of a Merchant Group Member pursuant to or in connection with the Principal AgreementDefined in clause 1.1(l) to) that proposed SubprocessorSubprocessormeans any person (including any third party and any Supplier Affiliate, but excluding an employee of Supplier or any of its sub-contractors) appointed by or on behalf of Supplier or any Supplier…Defined in clause 1.1(t) until reasonable steps have been taken to address the objections raised by any Merchant Group MemberMerchant Group Membermeans Merchant or any Merchant AffiliateDefined in clause 1.1(k) and MerchantMerchantTiny Company Pty Ltd has been provided with a reasonable written explanation of the steps taken.

6.5

With respect to each SubprocessorSubprocessormeans any person (including any third party and any Supplier Affiliate, but excluding an employee of Supplier or any of its sub-contractors) appointed by or on behalf of Supplier or any Supplier…Defined in clause 1.1(t), SupplierSupplierSupplier Pty Ltd or the relevant Supplier AffiliateSupplier Affiliatemeans an entity that owns or controls, is owned or controlled by or is or under common control or ownership with Supplier, where control is defined as the possession, directly or indirectly, of the…Defined in clause 1.1(m) shall:

(a)

before the SubprocessorSubprocessormeans any person (including any third party and any Supplier Affiliate, but excluding an employee of Supplier or any of its sub-contractors) appointed by or on behalf of Supplier or any Supplier…Defined in clause 1.1(t) first Processes Merchant Personal DataMerchant Personal Datameans any Personal Data Processed by a Contracted Processor on behalf of a Merchant Group Member pursuant to or in connection with the Principal AgreementDefined in clause 1.1(l) (or, where relevant, in accordance with clause 2), carry out adequate due diligence to ensure that the SubprocessorSubprocessormeans any person (including any third party and any Supplier Affiliate, but excluding an employee of Supplier or any of its sub-contractors) appointed by or on behalf of Supplier or any Supplier…Defined in clause 1.1(t) is capable of providing the level of protection for Merchant Personal DataMerchant Personal Datameans any Personal Data Processed by a Contracted Processor on behalf of a Merchant Group Member pursuant to or in connection with the Principal AgreementDefined in clause 1.1(l) required by the Principal Agreement;

(b)

ensure that the arrangement between on the one hand SupplierSupplierSupplier Pty Ltd, or the relevant Supplier AffiliateSupplier Affiliatemeans an entity that owns or controls, is owned or controlled by or is or under common control or ownership with Supplier, where control is defined as the possession, directly or indirectly, of the…Defined in clause 1.1(m), or the relevant intermediate SubprocessorSubprocessormeans any person (including any third party and any Supplier Affiliate, but excluding an employee of Supplier or any of its sub-contractors) appointed by or on behalf of Supplier or any Supplier…Defined in clause 1.1(t); and on the other hand the SubprocessorSubprocessormeans any person (including any third party and any Supplier Affiliate, but excluding an employee of Supplier or any of its sub-contractors) appointed by or on behalf of Supplier or any Supplier…Defined in clause 1.1(t), is governed by a written contract including terms which offer at least the same level of protection for Merchant Personal DataMerchant Personal Datameans any Personal Data Processed by a Contracted Processor on behalf of a Merchant Group Member pursuant to or in connection with the Principal AgreementDefined in clause 1.1(l) as those set out in this Agreement and meet the requirements of the Applicable LawsApplicable Lawsmeans : (i) European Union or Member State laws with respect to any Merchant Personal Data in respect of which any Merchant Group Member is subject to EU Data Protection Laws; and (ii) the UK Data…Defined in clause 1.1(a); and

(c)

provide to MerchantMerchantTiny Company Pty Ltd for review such copies of the Contracted ProcessorsContracted Processormeans Supplier or a SubprocessorDefined in clause 1.1(c)' agreements with SubprocessorsSubprocessormeans any person (including any third party and any Supplier Affiliate, but excluding an employee of Supplier or any of its sub-contractors) appointed by or on behalf of Supplier or any Supplier…Defined in clause 1.1(t) (which may be redacted to remove confidential commercial information not relevant to the requirements of this Agreement) as MerchantMerchantTiny Company Pty Ltd may request from time to time.

6.6

SupplierSupplierSupplier Pty Ltd and each Supplier AffiliateSupplier Affiliatemeans an entity that owns or controls, is owned or controlled by or is or under common control or ownership with Supplier, where control is defined as the possession, directly or indirectly, of the…Defined in clause 1.1(m) shall ensure that each SubprocessorSubprocessormeans any person (including any third party and any Supplier Affiliate, but excluding an employee of Supplier or any of its sub-contractors) appointed by or on behalf of Supplier or any Supplier…Defined in clause 1.1(t) performs the obligations under clause 3, clause 4, clause 5, clause 7.1, clause 8.2, clause 9.1 and clause 10.1, as they apply to ProcessingProcessingmeans any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring,…Defined in clause 1.1(n) of Merchant Personal DataMerchant Personal Datameans any Personal Data Processed by a Contracted Processor on behalf of a Merchant Group Member pursuant to or in connection with the Principal AgreementDefined in clause 1.1(l) carried out by that SubprocessorSubprocessormeans any person (including any third party and any Supplier Affiliate, but excluding an employee of Supplier or any of its sub-contractors) appointed by or on behalf of Supplier or any Supplier…Defined in clause 1.1(t), as if it were party to this Agreement in place of SupplierSupplierSupplier Pty Ltd.

7.

Data SubjectData Subjectmeans an Identifiable Natural Person about whom the Merchant or Supplier holds Personal Data and who is subject to the Data Protection LawsDefined in clause 1.1(d) Rights

7.1

SupplierSupplierSupplier Pty Ltd and each Supplier AffiliateSupplier Affiliatemeans an entity that owns or controls, is owned or controlled by or is or under common control or ownership with Supplier, where control is defined as the possession, directly or indirectly, of the…Defined in clause 1.1(m) will make available technical and organisational measures for the fulfilment of the Merchant Group MembersMerchant Group Membermeans Merchant or any Merchant AffiliateDefined in clause 1.1(k)' obligations to respond to requests to exercise any Data SubjectData Subjectmeans an Identifiable Natural Person about whom the Merchant or Supplier holds Personal Data and who is subject to the Data Protection LawsDefined in clause 1.1(d) rights under the Applicable LawsApplicable Lawsmeans : (i) European Union or Member State laws with respect to any Merchant Personal Data in respect of which any Merchant Group Member is subject to EU Data Protection Laws; and (ii) the UK Data…Defined in clause 1.1(a).

7.2

The MerchantMerchantTiny Company Pty Ltd authorises SupplierSupplierSupplier Pty Ltd, each Supplier AffiliateSupplier Affiliatemeans an entity that owns or controls, is owned or controlled by or is or under common control or ownership with Supplier, where control is defined as the possession, directly or indirectly, of the…Defined in clause 1.1(m), and each Contracted ProcessorContracted Processormeans Supplier or a SubprocessorDefined in clause 1.1(c) to comply with any request from a Data SubjectData Subjectmeans an Identifiable Natural Person about whom the Merchant or Supplier holds Personal Data and who is subject to the Data Protection LawsDefined in clause 1.1(d) under any Data Protection LawsData Protection Lawsmeans to the extent applicable: (i) the EU Data Protection Laws; (ii) the UK Data Protection Laws; (iii) the US Data Protection Laws; (iv) any data protection or privacy laws of: (A) The Commonwealth…Defined in clause 1.1(e) in respect of Merchant Personal DataMerchant Personal Datameans any Personal Data Processed by a Contracted Processor on behalf of a Merchant Group Member pursuant to or in connection with the Principal AgreementDefined in clause 1.1(l).

7.3

SupplierSupplierSupplier Pty Ltd shall notify the MerchantMerchantTiny Company Pty Ltd if SupplierSupplierSupplier Pty Ltd, any Supplier AffiliateSupplier Affiliatemeans an entity that owns or controls, is owned or controlled by or is or under common control or ownership with Supplier, where control is defined as the possession, directly or indirectly, of the…Defined in clause 1.1(m), or any Contracted ProcessorContracted Processormeans Supplier or a SubprocessorDefined in clause 1.1(c) receives a request from a Data SubjectData Subjectmeans an Identifiable Natural Person about whom the Merchant or Supplier holds Personal Data and who is subject to the Data Protection LawsDefined in clause 1.1(d) under any Data Protection LawsData Protection Lawsmeans to the extent applicable: (i) the EU Data Protection Laws; (ii) the UK Data Protection Laws; (iii) the US Data Protection Laws; (iv) any data protection or privacy laws of: (A) The Commonwealth…Defined in clause 1.1(e) in respect of Merchant Personal DataMerchant Personal Datameans any Personal Data Processed by a Contracted Processor on behalf of a Merchant Group Member pursuant to or in connection with the Principal AgreementDefined in clause 1.1(l).

8.

Personal Data BreachPersonal Data Breachmeans a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processedDefined in clause 1.1(q)

8.1

SupplierSupplierSupplier Pty Ltd shall notify MerchantMerchantTiny Company Pty Ltd without undue delay upon SupplierSupplierSupplier Pty Ltd or any SubprocessorSubprocessormeans any person (including any third party and any Supplier Affiliate, but excluding an employee of Supplier or any of its sub-contractors) appointed by or on behalf of Supplier or any Supplier…Defined in clause 1.1(t) becoming aware of a Personal Data BreachPersonal Data Breachmeans a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processedDefined in clause 1.1(q) affecting Merchant Personal DataMerchant Personal Datameans any Personal Data Processed by a Contracted Processor on behalf of a Merchant Group Member pursuant to or in connection with the Principal AgreementDefined in clause 1.1(l), providing MerchantMerchantTiny Company Pty Ltd with sufficient information to allow each Merchant Group MemberMerchant Group Membermeans Merchant or any Merchant AffiliateDefined in clause 1.1(k) to meet any obligations to report or inform Data SubjectsData Subjectmeans an Identifiable Natural Person about whom the Merchant or Supplier holds Personal Data and who is subject to the Data Protection LawsDefined in clause 1.1(d) of the Personal Data BreachPersonal Data Breachmeans a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processedDefined in clause 1.1(q) under the Applicable LawsApplicable Lawsmeans : (i) European Union or Member State laws with respect to any Merchant Personal Data in respect of which any Merchant Group Member is subject to EU Data Protection Laws; and (ii) the UK Data…Defined in clause 1.1(a).

8.2

SupplierSupplierSupplier Pty Ltd shall co-operate with MerchantMerchantTiny Company Pty Ltd and each Merchant Group MemberMerchant Group Membermeans Merchant or any Merchant AffiliateDefined in clause 1.1(k) and take such reasonable commercial steps as are directed by MerchantMerchantTiny Company Pty Ltd to assist in the investigation, mitigation and remediation of each such Personal Data BreachPersonal Data Breachmeans a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processedDefined in clause 1.1(q).

8.3

SupplierSupplierSupplier Pty Ltd shall maintain a register of all Personal Data BreachesPersonal Data Breachmeans a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processedDefined in clause 1.1(q) and provide reasonable access to such records as is necessary for the MerchantMerchantTiny Company Pty Ltd to comply with any Applicable LawsApplicable Lawsmeans : (i) European Union or Member State laws with respect to any Merchant Personal Data in respect of which any Merchant Group Member is subject to EU Data Protection Laws; and (ii) the UK Data…Defined in clause 1.1(a).

9.

Deletion or Return of Merchant Personal DataMerchant Personal Datameans any Personal Data Processed by a Contracted Processor on behalf of a Merchant Group Member pursuant to or in connection with the Principal AgreementDefined in clause 1.1(l)

9.1

Subject to clause 9.2 and clause 9.4, SupplierSupplierSupplier Pty Ltd and each Supplier AffiliateSupplier Affiliatemeans an entity that owns or controls, is owned or controlled by or is or under common control or ownership with Supplier, where control is defined as the possession, directly or indirectly, of the…Defined in clause 1.1(m) shall:

(a)

in the case of any live or operational data, promptly and in any event within 90 days; and

(b)

in the case of any data contained in systems backups, within 365 days;

of the date of cessation of any ServicesServicesmeans the services and other activities to be supplied to or carried out by or on behalf of Supplier for Merchant Group Members pursuant to the Principal AgreementDefined in clause 1.1(r) involving the ProcessingProcessingmeans any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring,…Defined in clause 1.1(n) of Merchant Personal DataMerchant Personal Datameans any Personal Data Processed by a Contracted Processor on behalf of a Merchant Group Member pursuant to or in connection with the Principal AgreementDefined in clause 1.1(l) (the Cessation DateCessation Date (inline)Defined in clause 9.1), delete and procure the deletion of all copies of those Merchant Personal DataMerchant Personal Datameans any Personal Data Processed by a Contracted Processor on behalf of a Merchant Group Member pursuant to or in connection with the Principal AgreementDefined in clause 1.1(l).

9.2

Subject to clause 9.4, MerchantMerchantTiny Company Pty Ltd may in its absolute discretion by written notice to SupplierSupplierSupplier Pty Ltd within 14 days of the Cessation DateCessation Date (inline)Defined in clause 9.1 require SupplierSupplierSupplier Pty Ltd and each Supplier AffiliateSupplier Affiliatemeans an entity that owns or controls, is owned or controlled by or is or under common control or ownership with Supplier, where control is defined as the possession, directly or indirectly, of the…Defined in clause 1.1(m) to return a complete copy of all Merchant Personal DataMerchant Personal Datameans any Personal Data Processed by a Contracted Processor on behalf of a Merchant Group Member pursuant to or in connection with the Principal AgreementDefined in clause 1.1(l) to MerchantMerchantTiny Company Pty Ltd by secure file transfer in such format as is reasonably notified by MerchantMerchantTiny Company Pty Ltd to SupplierSupplierSupplier Pty Ltd, or delete and procure the deletion of all other copies of Merchant Personal DataMerchant Personal Datameans any Personal Data Processed by a Contracted Processor on behalf of a Merchant Group Member pursuant to or in connection with the Principal AgreementDefined in clause 1.1(l) Processed by any Contracted ProcessorContracted Processormeans Supplier or a SubprocessorDefined in clause 1.1(c). SupplierSupplierSupplier Pty Ltd and each Supplier AffiliateSupplier Affiliatemeans an entity that owns or controls, is owned or controlled by or is or under common control or ownership with Supplier, where control is defined as the possession, directly or indirectly, of the…Defined in clause 1.1(m) shall comply with any such written request within 90 days of the Cessation DateCessation Date (inline)Defined in clause 9.1.

9.3

Where the Cessation DateCessation Date (inline)Defined in clause 9.1 occurs prior to the expiry of a prepaid term under the Principal Agreement, SupplierSupplierSupplier Pty Ltd shall refund to the MerchantMerchantTiny Company Pty Ltd a pro-rata amount of any prepaid fees, calculated as follows:

R = (F / T) x D

Where "R" is the refund amount

Where "F" is the total prepaid fees for the relevant term

Where "T" is the total number of days in the relevant term

Where "D" is the number of remaining days from the Cessation DateCessation Date (inline)Defined in clause 9.1 to the end of the relevant term

9.4

Each Contracted ProcessorContracted Processormeans Supplier or a SubprocessorDefined in clause 1.1(c) may retain Merchant Personal DataMerchant Personal Datameans any Personal Data Processed by a Contracted Processor on behalf of a Merchant Group Member pursuant to or in connection with the Principal AgreementDefined in clause 1.1(l) to the extent required by Applicable LawsApplicable Lawsmeans : (i) European Union or Member State laws with respect to any Merchant Personal Data in respect of which any Merchant Group Member is subject to EU Data Protection Laws; and (ii) the UK Data…Defined in clause 1.1(a) and only to the extent and for such period as required by Applicable LawsApplicable Lawsmeans : (i) European Union or Member State laws with respect to any Merchant Personal Data in respect of which any Merchant Group Member is subject to EU Data Protection Laws; and (ii) the UK Data…Defined in clause 1.1(a) and always provided that SupplierSupplierSupplier Pty Ltd and each Supplier AffiliateSupplier Affiliatemeans an entity that owns or controls, is owned or controlled by or is or under common control or ownership with Supplier, where control is defined as the possession, directly or indirectly, of the…Defined in clause 1.1(m) shall ensure the confidentiality of all such Merchant Personal DataMerchant Personal Datameans any Personal Data Processed by a Contracted Processor on behalf of a Merchant Group Member pursuant to or in connection with the Principal AgreementDefined in clause 1.1(l) and shall ensure that such Merchant Personal DataMerchant Personal Datameans any Personal Data Processed by a Contracted Processor on behalf of a Merchant Group Member pursuant to or in connection with the Principal AgreementDefined in clause 1.1(l) is only Processed as necessary for the purpose(s) specified in the Applicable LawsApplicable Lawsmeans : (i) European Union or Member State laws with respect to any Merchant Personal Data in respect of which any Merchant Group Member is subject to EU Data Protection Laws; and (ii) the UK Data…Defined in clause 1.1(a) requiring its storage and for no other purpose.

9.5

SupplierSupplierSupplier Pty Ltd shall provide written certification to MerchantMerchantTiny Company Pty Ltd that it and each Supplier AffiliateSupplier Affiliatemeans an entity that owns or controls, is owned or controlled by or is or under common control or ownership with Supplier, where control is defined as the possession, directly or indirectly, of the…Defined in clause 1.1(m) has fully complied with clause 9 within 90 days of the Cessation DateCessation Date (inline)Defined in clause 9.1.

10.

Audit Rights

10.1

Subject to clause 10.2, SupplierSupplierSupplier Pty Ltd and each Supplier AffiliateSupplier Affiliatemeans an entity that owns or controls, is owned or controlled by or is or under common control or ownership with Supplier, where control is defined as the possession, directly or indirectly, of the…Defined in clause 1.1(m) shall:

(a)

make reasonably available to each Merchant Group MemberMerchant Group Membermeans Merchant or any Merchant AffiliateDefined in clause 1.1(k) on request all information which must be made available under applicable Data Protection LawsData Protection Lawsmeans to the extent applicable: (i) the EU Data Protection Laws; (ii) the UK Data Protection Laws; (iii) the US Data Protection Laws; (iv) any data protection or privacy laws of: (A) The Commonwealth…Defined in clause 1.1(e); and

(b)

allow for and contribute to audits, including inspections of any SupplierSupplierSupplier Pty Ltd premises, by any Merchant Group MemberMerchant Group Membermeans Merchant or any Merchant AffiliateDefined in clause 1.1(k) or an auditor mandated by any Merchant Group MemberMerchant Group Membermeans Merchant or any Merchant AffiliateDefined in clause 1.1(k) required under any Data Protection LawsData Protection Lawsmeans to the extent applicable: (i) the EU Data Protection Laws; (ii) the UK Data Protection Laws; (iii) the US Data Protection Laws; (iv) any data protection or privacy laws of: (A) The Commonwealth…Defined in clause 1.1(e);

in relation to the ProcessingProcessingmeans any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring,…Defined in clause 1.1(n) of the Merchant Personal DataMerchant Personal Datameans any Personal Data Processed by a Contracted Processor on behalf of a Merchant Group Member pursuant to or in connection with the Principal AgreementDefined in clause 1.1(l) by the Contracted ProcessorsContracted Processormeans Supplier or a SubprocessorDefined in clause 1.1(c).

10.2

The MerchantMerchantTiny Company Pty Ltd or the relevant Merchant AffiliateMerchant Affiliatemeans an entity that owns or controls, is owned or controlled by or is or under common control or ownership with Merchant, where control is defined as the possession, directly or indirectly, of the…Defined in clause 1.1(j) undertaking an audit shall give SupplierSupplierSupplier Pty Ltd or the relevant Supplier AffiliateSupplier Affiliatemeans an entity that owns or controls, is owned or controlled by or is or under common control or ownership with Supplier, where control is defined as the possession, directly or indirectly, of the…Defined in clause 1.1(m) reasonable notice of any audit or inspection to be conducted under clause 10.1 and shall make (and ensure that each of its mandated auditors makes) reasonable endeavours to avoid causing (or, if it cannot avoid, to minimise) any damage, injury or disruption to the Contracted ProcessorsContracted Processormeans Supplier or a SubprocessorDefined in clause 1.1(c)' premises, equipment, personnel and business while its personnel are on those premises in the course of such an audit or inspection. A Contracted ProcessorContracted Processormeans Supplier or a SubprocessorDefined in clause 1.1(c) need not give access to its premises for the purposes of such an audit or inspection:

(a)

to any individual unless he or she produces reasonable evidence of identity and authority;

(b)

outside normal business hours at those premises, unless the audit or inspection needs to be conducted on an emergency basis and MerchantMerchantTiny Company Pty Ltd or the relevant Merchant AffiliateMerchant Affiliatemeans an entity that owns or controls, is owned or controlled by or is or under common control or ownership with Merchant, where control is defined as the possession, directly or indirectly, of the…Defined in clause 1.1(j) undertaking an audit has given notice to SupplierSupplierSupplier Pty Ltd or the relevant Supplier AffiliateSupplier Affiliatemeans an entity that owns or controls, is owned or controlled by or is or under common control or ownership with Supplier, where control is defined as the possession, directly or indirectly, of the…Defined in clause 1.1(m) that this is the case before attendance outside those hours begins; or

(c)

for the purposes of more than one audit or inspection, in respect of each Contracted ProcessorContracted Processormeans Supplier or a SubprocessorDefined in clause 1.1(c), in any calendar year, except for any audits or inspections which a Merchant Group MemberMerchant Group Membermeans Merchant or any Merchant AffiliateDefined in clause 1.1(k) is required or requested to carry out by Data Protection LawsData Protection Lawsmeans to the extent applicable: (i) the EU Data Protection Laws; (ii) the UK Data Protection Laws; (iii) the US Data Protection Laws; (iv) any data protection or privacy laws of: (A) The Commonwealth…Defined in clause 1.1(e), a Supervisory AuthoritySupervisory AuthorityDefined in clause 1.3 or any similar regulatory authority responsible for the enforcement of Data Protection LawsData Protection Lawsmeans to the extent applicable: (i) the EU Data Protection Laws; (ii) the UK Data Protection Laws; (iii) the US Data Protection Laws; (iv) any data protection or privacy laws of: (A) The Commonwealth…Defined in clause 1.1(e) in any country or territory, where MerchantMerchantTiny Company Pty Ltd or the relevant Merchant AffiliateMerchant Affiliatemeans an entity that owns or controls, is owned or controlled by or is or under common control or ownership with Merchant, where control is defined as the possession, directly or indirectly, of the…Defined in clause 1.1(j) undertaking an audit has identified the relevant requirement or request in its notice to SupplierSupplierSupplier Pty Ltd or the relevant Supplier AffiliateSupplier Affiliatemeans an entity that owns or controls, is owned or controlled by or is or under common control or ownership with Supplier, where control is defined as the possession, directly or indirectly, of the…Defined in clause 1.1(m) of the audit or inspection.

11.

International Transfers of Personal DataPersonal Datameans any information relating to an Identifiable Natural Person and includes the terms 'personal data' and 'personal information' under any applicable Data Protection LawsDefined in clause 1.1(o)

11.1

If SupplierSupplierSupplier Pty Ltd transfers any Personal DataPersonal Datameans any information relating to an Identifiable Natural Person and includes the terms 'personal data' and 'personal information' under any applicable Data Protection LawsDefined in clause 1.1(o) to SubprocessorsSubprocessormeans any person (including any third party and any Supplier Affiliate, but excluding an employee of Supplier or any of its sub-contractors) appointed by or on behalf of Supplier or any Supplier…Defined in clause 1.1(t) in countries which do not ensure an adequate level of data protection within the meaning of the Applicable LawsApplicable Lawsmeans : (i) European Union or Member State laws with respect to any Merchant Personal Data in respect of which any Merchant Group Member is subject to EU Data Protection Laws; and (ii) the UK Data…Defined in clause 1.1(a), SupplierSupplierSupplier Pty Ltd will take such measures as are necessary to ensure the transfer is in compliance with the Applicable LawsApplicable Lawsmeans : (i) European Union or Member State laws with respect to any Merchant Personal Data in respect of which any Merchant Group Member is subject to EU Data Protection Laws; and (ii) the UK Data…Defined in clause 1.1(a).

12.

GDPRGDPRmeans EU General Data Protection Regulation 2016/679Defined in clause 1.1(g) Specific Provisions

12.1

Addendum 1 to this Agreement sets out certain information regarding the Contracted ProcessorsContracted Processormeans Supplier or a SubprocessorDefined in clause 1.1(c)' ProcessingProcessingmeans any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring,…Defined in clause 1.1(n) of the Merchant Personal DataMerchant Personal Datameans any Personal Data Processed by a Contracted Processor on behalf of a Merchant Group Member pursuant to or in connection with the Principal AgreementDefined in clause 1.1(l) as required by article 28(3) of the GDPRGDPRmeans EU General Data Protection Regulation 2016/679Defined in clause 1.1(g) (and equivalent requirements of other Data Protection LawsData Protection Lawsmeans to the extent applicable: (i) the EU Data Protection Laws; (ii) the UK Data Protection Laws; (iii) the US Data Protection Laws; (iv) any data protection or privacy laws of: (A) The Commonwealth…Defined in clause 1.1(e)). Nothing in Addendum 1 (including as amended pursuant to clause 12) confers any right or imposes any obligation on any party to this Agreement.

12.2

SupplierSupplierSupplier Pty Ltd and each Supplier AffiliateSupplier Affiliatemeans an entity that owns or controls, is owned or controlled by or is or under common control or ownership with Supplier, where control is defined as the possession, directly or indirectly, of the…Defined in clause 1.1(m) shall provide reasonable assistance to each Merchant Group MemberMerchant Group Membermeans Merchant or any Merchant AffiliateDefined in clause 1.1(k) with any data protection impact assessments, and prior consultations with Supervisory AuthoritiesSupervisory AuthorityDefined in clause 1.3 or other competent data privacy authorities, which MerchantMerchantTiny Company Pty Ltd reasonably considers to be required of any Merchant Group MemberMerchant Group Membermeans Merchant or any Merchant AffiliateDefined in clause 1.1(k) by article 35 or 36 of the GDPRGDPRmeans EU General Data Protection Regulation 2016/679Defined in clause 1.1(g) or equivalent provisions of any other Data Protection LawsData Protection Lawsmeans to the extent applicable: (i) the EU Data Protection Laws; (ii) the UK Data Protection Laws; (iii) the US Data Protection Laws; (iv) any data protection or privacy laws of: (A) The Commonwealth…Defined in clause 1.1(e), in each case solely in relation to ProcessingProcessingmeans any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring,…Defined in clause 1.1(n) of Merchant Personal DataMerchant Personal Datameans any Personal Data Processed by a Contracted Processor on behalf of a Merchant Group Member pursuant to or in connection with the Principal AgreementDefined in clause 1.1(l) by, and taking into account the nature of the ProcessingProcessingmeans any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring,…Defined in clause 1.1(n) and information available to, the Contracted ProcessorsContracted Processormeans Supplier or a SubprocessorDefined in clause 1.1(c).

12.3

To the extent that SupplierSupplierSupplier Pty Ltd processes any personal data under this Agreement that originates from a GDPR ZoneGDPR Zonemeans : (i) The European Economic Area with respect to any Merchant Personal Data in respect of which any Merchant Group Member is subject to EU Data Protection Laws; or (ii) The United Kingdom of…Defined in clause 1.1(h) to a country that has not been designated by the CommissionCommissionDefined in clause 1.3 as providing an adequate level of protection for personal data, the parties agree to enter into the Standard Contractual ClausesStandard Contractual Clausesmeans : (i) the European Commission's Standard Contractual Clauses for the transfer of personal data from the European Union to processors established in third countries (controller-to-processor…Defined in clause 1.1(s), which are hereby incorporated into and form part of this Agreement. The parties hereby agree that:

(a)

Data processing details set out in Addendum 1 of this Agreement shall apply for the purposes of Appendix 1 of the Standard Contractual ClausesStandard Contractual Clausesmeans : (i) the European Commission's Standard Contractual Clauses for the transfer of personal data from the European Union to processors established in third countries (controller-to-processor…Defined in clause 1.1(s);

(b)

The technical and organizational security measures set out in Addendum 2 of this Agreement shall apply for the purpose of Appendix 2 to the Standard Contractual ClausesStandard Contractual Clausesmeans : (i) the European Commission's Standard Contractual Clauses for the transfer of personal data from the European Union to processors established in third countries (controller-to-processor…Defined in clause 1.1(s); and

(c)

SupplierSupplierSupplier Pty Ltd shall be deemed the "data importer" and the MerchantMerchantTiny Company Pty Ltd the "data exporter" under the Standard Contractual ClausesStandard Contractual Clausesmeans : (i) the European Commission's Standard Contractual Clauses for the transfer of personal data from the European Union to processors established in third countries (controller-to-processor…Defined in clause 1.1(s).

13.

US Privacy Law Specific Provisions

13.1

SupplierSupplierSupplier Pty Ltd is a "Service Provider" for the purpose of any relevant US Data Protection LawsUS Data Protection Lawsmeans the CCPA, the Colorado Privacy Act, Colorado Rev. Stat. 6-1-1301 et seq. (the CPA); the Connecticut Act Concerning Personal Data Protection and Online Monitoring, Conn. PA 22-15 § 1 et seq.…Defined in clause 1.1(w). The MerchantMerchantTiny Company Pty Ltd discloses personal data to SupplierSupplierSupplier Pty Ltd solely for:

(a)

a valid business purpose; and

(b)

for SupplierSupplierSupplier Pty Ltd to perform the ServicesServicesmeans the services and other activities to be supplied to or carried out by or on behalf of Supplier for Merchant Group Members pursuant to the Principal AgreementDefined in clause 1.1(r).

13.2

To the extent that any US Data Protection LawsUS Data Protection Lawsmeans the CCPA, the Colorado Privacy Act, Colorado Rev. Stat. 6-1-1301 et seq. (the CPA); the Connecticut Act Concerning Personal Data Protection and Online Monitoring, Conn. PA 22-15 § 1 et seq.…Defined in clause 1.1(w) apply, SupplierSupplierSupplier Pty Ltd will not, and will not authorise its SubprocessorsSubprocessormeans any person (including any third party and any Supplier Affiliate, but excluding an employee of Supplier or any of its sub-contractors) appointed by or on behalf of Supplier or any Supplier…Defined in clause 1.1(t) to, re-identify any de-identified, anonymized, or pseudonymized data derived from personal data that is Processed by SupplierSupplierSupplier Pty Ltd on behalf of the MerchantMerchantTiny Company Pty Ltd, unless instructed by MerchantMerchantTiny Company Pty Ltd in writing.

14.

General Terms

14.1

Governing Law and Jurisdiction

(a)

The parties to this Agreement hereby submit to the choice of jurisdiction stipulated in the Principal Agreement with respect to any disputes or claims howsoever arising under this Agreement, including disputes regarding its existence, validity or termination or the consequences of its nullity; and

(b)

This Agreement and all non-contractual or other obligations arising out of or in connection with it are governed by the laws of the country or territory stipulated for this purpose in the Principal Agreement.

14.2

Order of Precedence

(a)

Nothing in this Agreement reduces SupplierSupplierSupplier Pty Ltd's or any Supplier AffiliateSupplier Affiliatemeans an entity that owns or controls, is owned or controlled by or is or under common control or ownership with Supplier, where control is defined as the possession, directly or indirectly, of the…Defined in clause 1.1(m)'s obligations under the Principal Agreement in relation to the protection of Personal DataPersonal Datameans any information relating to an Identifiable Natural Person and includes the terms 'personal data' and 'personal information' under any applicable Data Protection LawsDefined in clause 1.1(o) or permits SupplierSupplierSupplier Pty Ltd or any Supplier AffiliateSupplier Affiliatemeans an entity that owns or controls, is owned or controlled by or is or under common control or ownership with Supplier, where control is defined as the possession, directly or indirectly, of the…Defined in clause 1.1(m) to Process (or permit the ProcessingProcessingmeans any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring,…Defined in clause 1.1(n) of) Personal DataPersonal Datameans any information relating to an Identifiable Natural Person and includes the terms 'personal data' and 'personal information' under any applicable Data Protection LawsDefined in clause 1.1(o) in a manner which is prohibited by the Principal Agreement.

(b)

Subject to clause 3, with regard to the subject matter of this Agreement, in the event of inconsistencies between the provisions of this Agreement and any other agreements between the parties, including the Principal Agreement and including (except where explicitly agreed otherwise in writing, signed on behalf of the parties) agreements entered into or purported to be entered into after the date of this Agreement, the provisions of this Agreement shall prevail.

14.3

Changes in Data Protection LawsData Protection Lawsmeans to the extent applicable: (i) the EU Data Protection Laws; (ii) the UK Data Protection Laws; (iii) the US Data Protection Laws; (iv) any data protection or privacy laws of: (A) The Commonwealth…Defined in clause 1.1(e)

(a)

MerchantMerchantTiny Company Pty Ltd may propose any other variations to this Agreement which MerchantMerchantTiny Company Pty Ltd reasonably considers to be necessary to address the requirements of any Data Protection LawsData Protection Lawsmeans to the extent applicable: (i) the EU Data Protection Laws; (ii) the UK Data Protection Laws; (iii) the US Data Protection Laws; (iv) any data protection or privacy laws of: (A) The Commonwealth…Defined in clause 1.1(e).

14.4

Severance

(a)

Should any provision of this Agreement be invalid or unenforceable, then the remainder of this Agreement shall remain valid and in force. The invalid or unenforceable provision shall be either:

(i)

amended as necessary to ensure its validity and enforceability, while preserving the parties' intentions as closely as possible; or, if this is not possible,

(ii)

construed in a manner as if the invalid or unenforceable part had never been contained therein.

Addendum 1Details of Processing of Merchant Personal Data

This Addendum 1 includesincludeDefined in clause 1.4 certain details of the ProcessingProcessingmeans any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring,…Defined in clause 1.1(n) of Merchant Personal DataMerchant Personal Datameans any Personal Data Processed by a Contracted Processor on behalf of a Merchant Group Member pursuant to or in connection with the Principal AgreementDefined in clause 1.1(l) as required by Article 28(3) GDPRGDPRmeans EU General Data Protection Regulation 2016/679Defined in clause 1.1(g).

1.

List of Parties

1.1

Data Exporter

(a)

Name: The entity identified as the MerchantMerchantTiny Company Pty Ltd on this Agreement.

(b)

Address: The MerchantMerchantTiny Company Pty Ltd's Billing Address specified in the MerchantMerchantTiny Company Pty Ltd's account.

(c)

Contact person's name, position and contact details: The Primary Contact Name, Primary Contact Position and Primary Contact Email in the MerchantMerchantTiny Company Pty Ltd's account.

(d)

Activities relevant to the data transferred under these Clauses: The data exporter is a customer of the data importer and utilising the data importer's services to conduct ecommerce customer review requests.

(e)

Role (controller/processor): ControllerControllerDefined in clause 1.3

1.2

Data Importer

(a)

Name: SupplierSupplierSupplier Pty Ltd.

(b)

Address: SupplierSupplierSupplier Pty Ltd Pty Ltd, 123 Fake St, NSW Australia.

(c)

Contact person's name, position and contact details: John Smith, Data Protection Officer, john.smith@supplier.com.

(d)

Activities relevant to the data transferred under these Clauses: The data importer operates an ecommerce marketing platform and service.

(e)

Role (controller/processor): Processor

Addendum 2Technical and Organisational Safety Measures

SupplierSupplierSupplier Pty Ltd will maintain administrative, physical and technical safeguards designed to protect the security, confidentiality and integrity of the MerchantMerchantTiny Company Pty Ltd's personal data Processed by SupplierSupplierSupplier Pty Ltd, as described in the Principal Agreement and this Agreement.

SupplierSupplierSupplier Pty Ltd will not materially decrease the overall security of the ServicesServicesmeans the services and other activities to be supplied to or carried out by or on behalf of Supplier for Merchant Group Members pursuant to the Principal AgreementDefined in clause 1.1(r) during a subscription term.

Addendum 3Standard Contractual Clauses - Supplementary Terms To Provide Additional Safeguards

This ADDENDUM is supplemental to, and should be read in conjunction with, the Standard Contractual ClausesStandard Contractual Clausesmeans : (i) the European Commission's Standard Contractual Clauses for the transfer of personal data from the European Union to processors established in third countries (controller-to-processor…Defined in clause 1.1(s). Any references to the 'Clauses' in this ADDENDUM should be read as references to the Standard Contractual ClausesStandard Contractual Clausesmeans : (i) the European Commission's Standard Contractual Clauses for the transfer of personal data from the European Union to processors established in third countries (controller-to-processor…Defined in clause 1.1(s).

The data importer agrees and warrants:

1

without prejudice to Clause 5(b) of the Clauses, that, in the event the Clauses cease to be an appropriate safeguard for the transfer of the personal data as described in Appendix 1 of the Clauses, in accordance with applicable Data Protection LawsData Protection Lawsmeans to the extent applicable: (i) the EU Data Protection Laws; (ii) the UK Data Protection Laws; (iii) the US Data Protection Laws; (iv) any data protection or privacy laws of: (A) The Commonwealth…Defined in clause 1.1(e), by virtue of a binding decision by a competent Supervisory AuthoritySupervisory AuthorityDefined in clause 1.3, or at the discretion of the data exporter as notified to the data importer, the data exporter shall be entitled to suspend the transfer of data and/or terminate the contract;

2

to assist the data exporter with the data exporter's continuing assessment of the adequacy of the protection of the personal data in accordance with the requirements of the applicable Data Protection LawsData Protection Lawsmeans to the extent applicable: (i) the EU Data Protection Laws; (ii) the UK Data Protection Laws; (iii) the US Data Protection Laws; (iv) any data protection or privacy laws of: (A) The Commonwealth…Defined in clause 1.1(e) and pursuant to Clause 5(a) of the Clauses; and

3

that, in the event the data transfer and data processing activities are suspended or terminated pursuant to the Clauses or this ADDENDUM, its cessation of the data processing activities will not be prevented by, or be in breach of, and will not give rise to any third party rights or remedies pursuant to, any binding obligation on the data importer under the Clauses or any other agreement between the data importer and the data exporter (or any of its affiliates) in relation to the personal data and data processing activities.

Addendum 4List of Sub-processors

The MerchantMerchantTiny Company Pty Ltd has authorised the use of the SubprocessorsSubprocessormeans any person (including any third party and any Supplier Affiliate, but excluding an employee of Supplier or any of its sub-contractors) appointed by or on behalf of Supplier or any Supplier…Defined in clause 1.1(t) set out at: https://www.supplier.io/gdpr/

Exhibit 1Site Plan

Site Plan

Exhibit 2Technical Drawings

./exhibits/drawings.pdf

Exhibit 3Placeholder Only

Exhibit 3 — Placeholder Only

Schedule

ItemParticulars
Objection Period