Anteriq Data Processing Addendum
PARTIES
(1) The financial planning firm or other customer entity that accepts or is party to Anteriq’s Terms of Service or another written or electronic agreement governing use of the Service (the “Customer”).
(2) Anteriq, LLC, a Colorado limited liability company, with offices located at 11479 S Pine Dr, Parker, CO 80134 (“Anteriq”).
RECITALS
WHEREAS, the Customer and Anteriq are parties to Anteriq’s Terms of Service or another written or electronic agreement governing the Customer’s use of the Service (the “Agreement”), under which Anteriq may process Customer Personal Data in connection with its cloud software-as-a-service platform and related services; and
WHEREAS, this Data Processing Addendum (the “DPA”) supplements and is incorporated into the Agreement and sets out the additional terms, requirements, and conditions on which Anteriq will obtain, handle, process, disclose, transfer, or store Customer Personal Data when providing the Service;
NOW, THEREFORE, in consideration of the mutual covenants and agreements hereinafter set forth and for other good and valuable consideration, the receipt and sufficiency of which are hereby acknowledged, the parties hereto agree as follows:
The Customer agrees to this DPA by executing the Agreement, by accepting this DPA electronically, or by accessing or using the Service after this DPA is made available. Signature of this DPA is not required for it to be binding.
-
Definitions and Interpretation
- The following definitions and rules of interpretation apply in this DPA.
“Business Purpose” means providing the Service described in the Agreement, including hosting, supporting, maintaining, securing, and improving Anteriq’s U.S.-based cloud SaaS practice-management and client-operations platform for financial planning firms, and any other purpose specifically identified in Appendix A.
“Data Subject” means an individual who is the subject of Customer Personal Data and to whom or about whom the Customer Personal Data relates or identifies, directly or indirectly, including an end-client, representative, employee, contractor, or other individual whose information is submitted to the Service by or on behalf of the Customer.
“Customer Personal Data” means any information Anteriq processes for the Customer that (a) identifies or relates to an individual who can be identified directly or indirectly from that data alone or in combination with other information in Anteriq’s possession or control or that Anteriq is likely to have access to, including end-client financial information submitted to the Service, or (b) the relevant Privacy and Data Protection Requirements otherwise define as protected personal information, personal data, personal information, nonpublic personal information, or similar regulated information.
“Processing, processes, or process” means any activity that involves the use of Customer Personal Data or that the relevant Privacy and Data Protection Requirements may otherwise include in the definition of processing, processes, or process. It includes obtaining, recording, or holding the data, or carrying out any operation or set of operations on the data including, but not limited to, organizing, amending, retrieving, using, disclosing, erasing, or destroying it. Processing also includes transferring Customer Personal Data to third parties.
“Privacy and Data Protection Requirements” means all applicable U.S. federal and state laws and regulations relating to the processing, protection, or privacy of Customer Personal Data, including, where applicable, the Gramm-Leach-Bliley Act and its implementing Safeguards Rule, the California Consumer Privacy Act as amended by the California Privacy Rights Act, the Colorado Privacy Act, and other applicable U.S. state consumer privacy laws.
“Security Incident” means any confirmed act or omission that compromises the security, confidentiality, or integrity of Customer Personal Data or the physical, technical, administrative, or organizational safeguards put in place to protect it, where such act or omission is reasonably likely to result in unauthorized access, disclosure, acquisition, or use of Customer Personal Data that would constitute a breach or security incident requiring notification under applicable Privacy and Data Protection Requirements.
-
This DPA is subject to the terms of the Agreement, supplements the Agreement, and is incorporated into the Agreement. Interpretations and defined terms set forth in the Agreement apply to the interpretation of this DPA, except that this DPA controls with respect to the processing of Customer Personal Data.
-
The Appendices form part of this DPA and will have effect as if set out in full in the body of this DPA. Any reference to this DPA includes the Appendices.
-
A reference to “writing” or “written” includes email.
-
In the case of conflict or ambiguity between:
-
any provision contained in the body of this DPA and any provision contained in the Appendices, the provision in the body of this DPA will prevail;
-
the terms of any accompanying invoice or other documents annexed to this DPA and any provision contained in the Appendices, the provision contained in the Appendices will prevail;
-
any of the provisions of this DPA and the provisions of the Agreement, the provisions of this DPA will prevail with respect to the processing of Customer Personal Data.
-
-
Customer Personal Data Types and Processing Purposes
-
The Customer retains control of Customer Personal Data and remains responsible for its compliance obligations under the applicable Privacy and Data Protection Requirements as the controller, business, financial institution, or equivalent responsible party, including providing any required notices and obtaining any required consents, and for the processing instructions it gives to Anteriq.
-
Appendix A describes the general Customer Personal Data categories and related types of Data Subjects Anteriq may process to fulfill the Business Purposes of the Agreement. The Customer discloses Customer Personal Data to Anteriq only for the limited and specified Business Purposes.
-
-
Anteriq’s Service Provider and Processor Obligations
-
Anteriq will process, retain, use, or disclose Customer Personal Data only to the extent, and in such a manner, as is necessary for the Business Purposes and in accordance with the Customer’s lawful written instructions. Anteriq will not process, retain, use, or disclose Customer Personal Data for any other purpose, outside of the parties’ business relationship, or in a way that does not comply with this DPA or the Privacy and Data Protection Requirements. Anteriq will not sell Customer Personal Data, share Customer Personal Data for cross-context behavioral advertising, process Customer Personal Data for targeted advertising, or combine Customer Personal Data with personal information Anteriq receives from or on behalf of another person or collects from its own interactions with an individual, except as permitted for service providers or processors under applicable U.S. state privacy laws. Anteriq must promptly notify the Customer if, in its opinion, the Customer’s instruction would not comply with the Privacy and Data Protection Requirements.
-
Anteriq must promptly comply with any lawful Customer request or instruction requiring Anteriq to amend, transfer, or delete Customer Personal Data, or to stop, mitigate, or remedy any unauthorized processing.
-
Anteriq will maintain the confidentiality of all Customer Personal Data and will not sell it to anyone, share it for cross-context behavioral advertising or targeted advertising with anyone, or disclose it to third parties without specific authorization from the Customer or this DPA, unless required by law. If a law requires Anteriq to process or disclose Customer Personal Data, Anteriq must first inform the Customer of the legal requirement and give the Customer an opportunity to object or challenge the requirement, unless the law prohibits such notice.
-
Anteriq will reasonably assist the Customer with meeting the Customer’s compliance obligations under the Privacy and Data Protection Requirements, taking into account the nature of Anteriq’s processing and the information available to Anteriq. Any such assistance that exceeds a reasonable baseline related to Anteriq’s core services and obligations under this DPA will be provided at the Customer’s cost at Anteriq’s then-current professional services rates, which Anteriq will communicate to the Customer in advance.
-
Anteriq must promptly notify the Customer of any changes to Privacy and Data Protection Requirements, or its ability to meet those obligations, that may adversely affect Anteriq’s performance of the Agreement or this DPA.
-
The Customer acknowledges that Anteriq is under no duty to investigate the completeness, accuracy, or sufficiency of any specific Customer instructions or Customer Personal Data other than as required under the Privacy and Data Protection Requirements.
-
To the extent Anteriq collects Customer Personal Data directly for the Customer through the Service, Anteriq will do so only using a notice or method that the Customer specifically pre-approves in writing or that the Customer has configured or enabled through the Service, and that contains an approved privacy notice informing the Data Subject of the Customer’s identity, the purpose or purposes for which their Customer Personal Data will be processed, and any other information required by applicable Privacy and Data Protection Requirements. Anteriq will not materially modify that notice in any way without the Customer’s prior written consent.
-
-
Confidentiality and Personnel Access Controls
-
Anteriq will limit Customer Personal Data access to:
-
those employees, contractors, and personnel who require Customer Personal Data access to meet Anteriq’s obligations under this DPA and the Agreement; and
-
the part or parts of the Customer Personal Data that those personnel strictly require for the performance of their duties.
-
-
Anteriq will ensure that all personnel with access to Customer Personal Data:
-
are informed of the Customer Personal Data’s confidential nature and use restrictions and are obliged to keep the Customer Personal Data confidential;
-
receive training appropriate to their roles on the Privacy and Data Protection Requirements relating to handling Customer Personal Data and how those requirements apply to their particular duties; and
-
are aware both of Anteriq’s duties and their personal duties and obligations under the Privacy and Data Protection Requirements and this DPA.
-
-
Anteriq will take reasonable steps to ensure the reliability, integrity, and trustworthiness of personnel with access to Customer Personal Data, including background checks where appropriate and consistent with applicable law.
-
-
Security
-
Anteriq must at all times implement appropriate technical and organizational measures designed to safeguard Customer Personal Data against unauthorized or unlawful processing, access, copying, modification, storage, reproduction, display, or distribution, and against accidental loss, destruction, unavailability, or damage, including the security measures set out in Appendix B. Anteriq must document those measures in writing and periodically review them, at least annually, to ensure they remain current and complete.
-
Anteriq will maintain a written information security program reasonably designed to protect Customer Personal Data and, where Customer is subject to the Gramm-Leach-Bliley Act Safeguards Rule, will implement appropriate safeguards for Customer Personal Data and require applicable service providers that process such data on Anteriq’s behalf to maintain safeguards reasonably designed to protect it.
-
Anteriq must take reasonable precautions to preserve the integrity of any Customer Personal Data it processes and to prevent any corruption or loss of Customer Personal Data, including establishing backup and data restoration procedures appropriate to the Service.
-
-
Security Incidents and Customer Personal Data Loss
-
Anteriq will promptly notify the Customer if Customer Personal Data is lost or destroyed or becomes damaged, corrupted, or unusable due to Anteriq’s systems or acts or omissions. Anteriq will use commercially reasonable efforts to restore such Customer Personal Data from available backups or other available sources.
-
Anteriq will provide written notice to the Customer without undue delay and, where feasible, no later than 72 hours after confirmation if it becomes aware of:
-
any unauthorized or unlawful processing of Customer Personal Data; or
-
any Security Incident.
-
-
Immediately following any unauthorized or unlawful Customer Personal Data processing or Security Incident, the parties will coordinate with each other to investigate the matter. Initial notice under Section 6.2 may be preliminary in nature, provided that Anteriq supplements such notice with additional information as it becomes available. Anteriq will reasonably cooperate with the Customer in the Customer’s handling of the matter, including:
-
assisting with any investigation;
-
providing the Customer with information reasonably available to Anteriq regarding facilities and operations affected;
-
facilitating reasonable communications with Anteriq personnel involved in the matter; and
-
making available relevant records, logs, files, data reporting, and other materials reasonably required to comply with applicable Privacy and Data Protection Requirements or as otherwise reasonably required by the Customer.
-
-
Anteriq will not inform any third party of a Security Incident involving Customer Personal Data without first obtaining the Customer’s prior written consent, except when law or regulation requires it or when disclosure is reasonably necessary to investigate, contain, remediate, or obtain professional advice regarding the Security Incident.
-
The Customer has the right to determine the matters set out in Section 6.5(a) and 6.5(b) below, provided that, where such determination is reasonably likely to result in costs or reimbursement obligations for Anteriq under Sections 6.6 or 6.7, the Customer will consult with Anteriq in good faith prior to taking action and will obtain Anteriq’s prior written consent, not to be unreasonably withheld, conditioned, or delayed:
-
whether to provide notice of the Security Incident to any affected individuals, regulators, law enforcement agencies, or others, as required by law or regulation or in the Customer’s discretion, including the contents and delivery method of the notice; and
-
whether to offer any type of remedy to affected individuals, including the nature and extent of such remedy.
-
-
Anteriq will cover all reasonable expenses associated with the performance of the obligations under Section 6.2 and Section 6.3 to the extent that the Security Incident or unauthorized processing was caused by Anteriq’s acts, omissions, negligence, or breach of this DPA. The Customer will cover all reasonable expenses to the extent the matter arose from the Customer’s specific instructions, negligence, willful default, or breach of this DPA. Where both parties contributed to the matter, expenses will be allocated proportionally to each party’s relative fault.
-
Anteriq will also reimburse the Customer for actual reasonable expenses the Customer incurs when responding to and mitigating damages, to the extent that Anteriq caused a Security Incident, including legally required costs of notice and any remedy as set out in Section 6.5.
-
-
U.S. Processing Location
-
Anteriq will receive, access, process, and store Customer Personal Data only in the United States unless the Customer provides prior written consent or the parties separately agree in writing. This location commitment applies to Anteriq’s own processing of Customer Personal Data. Anteriq’s subprocessors operate their own infrastructure under their own regional practices, and this Section does not state where a subprocessor processes data; Anteriq remains responsible for its subprocessors as set out in Section 8. This DPA does not incorporate, and Anteriq does not agree to, GDPR, UK GDPR, Swiss data protection law, Standard Contractual Clauses, or other cross-border transfer mechanisms unless separately agreed in writing by Anteriq.
-
Anteriq will provide reasonable advance written notice to the Customer before materially changing the locations from which it receives, accesses, processes, or stores Customer Personal Data.
-
-
Subprocessors
-
Anteriq may authorize a third party subprocessor to process Customer Personal Data only if:
-
Anteriq provides at least 30 days’ advance notice of any new or replacement subprocessor, which may be provided through the Service, email, a posted subprocessor list, or another reasonable electronic method. If the Customer objects on reasonable data protection or security grounds during that notice period, the parties will meet and confer in good faith to resolve the objection. If the parties cannot resolve the objection, the Customer may terminate the affected Service to the extent permitted by the Agreement;
-
Anteriq enters into a written contract with the subprocessor that imposes data protection obligations substantially similar to those set out in this DPA;
-
Anteriq remains responsible for Customer Personal Data it entrusts to the subprocessor; and
-
the subprocessor is authorized to process Customer Personal Data only for the Business Purposes and in accordance with Anteriq’s instructions.
-
-
Anteriq will maintain a list of approved subprocessors in Appendix A or in another location made reasonably available to the Customer, including each subprocessor’s name and service function.
-
Where the subprocessor fails to fulfill its obligations under such written agreement, Anteriq remains responsible to the Customer for the subprocessor’s performance of its data protection obligations.
-
The parties consider Anteriq to control any Customer Personal Data controlled by or in the possession of its subprocessors for purposes of Anteriq’s obligations under this DPA.
-
Upon the Customer’s reasonable written request, Anteriq will provide information reasonably available to Anteriq regarding a subprocessor’s compliance with its obligations for Customer Personal Data, subject to confidentiality, security, and legal restrictions.
-
-
Consumer and End-Client Privacy Requests
-
Anteriq must notify the Customer within 5 working days if it receives a request from a Data Subject, consumer, or end-client to exercise any rights the individual may have regarding their Customer Personal Data, such as access, correction, deletion, portability, or opt-out or limitation rights under applicable Privacy and Data Protection Requirements.
-
Anteriq must notify the Customer promptly if it receives any other complaint, notice, or communication that directly or indirectly relates to Customer Personal Data processing or to either party’s compliance with the Privacy and Data Protection Requirements.
-
Anteriq will provide reasonable cooperation and assistance in responding to any complaint, notice, communication, or Data Subject, consumer, or end-client request, including by implementing reasonable technical and organizational measures that enable the Customer to respond to verified requests as required by applicable Privacy and Data Protection Requirements. Any such cooperation or assistance that is material in scope or volume and exceeds a reasonable baseline related to Anteriq’s obligations under this DPA will be provided at the Customer’s cost at Anteriq’s then-current professional services rates, which Anteriq will communicate to the Customer in advance.
-
Anteriq must not disclose Customer Personal Data to any Data Subject or to a third party unless the disclosure is at the Customer’s request or instruction, permitted by this DPA, or otherwise required by law.
-
-
Term and Termination
-
This DPA will remain in full force and effect so long as:
-
the Agreement remains in effect; or
-
Anteriq retains any Customer Personal Data related to the Agreement in its possession or control (the “Term”).
-
-
Any provision of this DPA that expressly or by implication should come into or continue in force on or after termination of the Agreement in order to protect Customer Personal Data will remain in full force and effect.
-
Anteriq’s material failure to comply with the terms of this DPA is a material breach of the Agreement. In such event, the Customer may exercise its remedies under the Agreement for the affected Service.
-
If a change in any Privacy and Data Protection Requirement or either party’s circumstances prevents a party from fulfilling all or part of its Agreement obligations, the parties will work in good faith to modify the affected processing of Customer Personal Data to comply with the requirements. If the parties are unable to bring the Customer Personal Data processing into compliance with the Privacy and Data Protection Requirements within 30 days, either party may terminate the affected Service upon written notice to the other party to the extent permitted by the Agreement.
-
-
Data Return and Destruction
-
For 30 days following termination or expiration of the Agreement, Anteriq will make available a reasonable export of Customer Personal Data in its possession or control through the Service or another commercially reasonable method, unless prohibited by law or the Agreement.
-
After the 30-day post-termination export window, Anteriq will securely destroy or de-identify Customer Personal Data in its possession or control in accordance with its standard deletion practices, unless the Customer has requested return or deletion earlier or retention is required by law, the Agreement, backup practices, or legitimate business recordkeeping obligations.
-
If any law, regulation, government or regulatory body, backup process, or legitimate business recordkeeping obligation requires Anteriq to retain any documents or materials that Anteriq would otherwise be required to return or destroy, Anteriq may retain such materials only for that retention reason, backup purpose, legal compliance, dispute resolution, security, or audit purpose and will continue to protect retained Customer Personal Data under this DPA.
-
Upon the Customer’s reasonable written request, Anteriq will certify in writing that it has completed deletion of Customer Personal Data, subject to the retention exceptions described in this DPA.
-
-
Records
-
Anteriq will keep records regarding its processing of Customer Personal Data as reasonably necessary to demonstrate compliance with this DPA and applicable Privacy and Data Protection Requirements, including records relating to access, control, security, approved subprocessors, processing purposes, and other records required by applicable law (the “Records”).
-
Anteriq will ensure that the Records are sufficient to enable the Customer to verify Anteriq’s compliance with its obligations under this DPA, subject to confidentiality, security, legal privilege, and protection of other customers’ information.
-
The Customer and Anteriq must review the information listed in the Appendices to this DPA periodically to confirm its current accuracy and update it when required to reflect current practices.
-
-
Audit
-
Upon the Customer’s reasonable written request no more than once per calendar year, Anteriq will make available information reasonably necessary to demonstrate compliance with this DPA, which may include security summaries, questionnaire responses, policies, certifications, or independent assessment materials then available to Anteriq. Any review must be conducted during normal business hours, on reasonable prior notice, in a manner that does not unreasonably disrupt Anteriq’s operations or compromise the security or confidentiality of Anteriq’s systems or other customers’ information.
-
Upon the Customer’s written request, Anteriq will make relevant security and compliance information available for review to the extent then available and appropriate, including as applicable security summaries, vulnerability assessment summaries, and other reasonably relevant materials. The Customer will treat such materials as Anteriq’s confidential information under the Agreement.
-
Anteriq will promptly address material issues, concerns, or exceptions identified through such review with the development and implementation of a reasonable corrective action plan by Anteriq’s management.
-
-
Warranties
-
Anteriq warrants and represents that:
-
its employees, agents, and any other person or persons under Anteriq’s direct control accessing Customer Personal Data on its behalf are reliable and trustworthy and receive appropriate training on the Privacy and Data Protection Requirements relating to Customer Personal Data, and, with respect to subprocessors, that Anteriq engages such subprocessors under written agreements imposing data protection obligations substantially similar to those set out in this DPA as required by Section 8; and
-
it and anyone operating on its behalf will process Customer Personal Data in compliance with both the terms of this DPA and all applicable Privacy and Data Protection Requirements and other laws, enactments, regulations, orders, standards, and other similar instruments; and
-
it has no reason to believe that any applicable Privacy and Data Protection Requirements prevent it from providing the contracted Service under the Agreement; and
-
considering the current technology environment and implementation costs, it will take appropriate technical and organizational measures to prevent the unauthorized or unlawful processing of Customer Personal Data and the accidental loss or destruction of, or damage to, Customer Personal Data, and ensure a level of security appropriate to:
-
the harm that might result from such unauthorized or unlawful processing or accidental loss, destruction, or damage;
-
the nature of the Customer Personal Data protected; and
-
it and anyone operating on its behalf will comply with all applicable Privacy and Data Protection Requirements and Anteriq’s information security policies, including the security measures required in Section 5.1 and Appendix B.
-
-
-
The Customer warrants and represents that Anteriq’s expected use of Customer Personal Data for the Business Purpose and as specifically instructed by the Customer will comply with all Privacy and Data Protection Requirements.
-
-
Indemnification
-
Anteriq agrees to indemnify, keep indemnified, and defend at its own expense the Customer against all costs, claims, damages, or expenses incurred by the Customer or for which the Customer may become liable due to any failure by Anteriq or its employees, subprocessors, or agents to comply with any of its obligations under this DPA or applicable Privacy and Data Protection Requirements, subject to the limitations of liability and exclusions in the Agreement, except to the extent prohibited by applicable law.
-
Except as expressly provided in this DPA, the Agreement’s limitation of liability, exclusions, disclaimers, dispute resolution terms, and other risk-allocation provisions apply to this DPA.
-
During the Term, Anteriq will maintain commercially reasonable insurance coverage appropriate to its business and the Service. Upon the Customer’s reasonable written request, Anteriq will provide evidence of such coverage, subject to confidentiality and insurer restrictions.
-
-
Notice
- Any notice or other communication given to a party under or in connection with this DPA must be in writing and delivered to the notice address or contact specified in the Agreement or otherwise designated by the receiving party in writing. Privacy and security notices to Anteriq may be sent to Anteriq, LLC, 11479 S Pine Dr, Parker, CO 80134, or any privacy or security contact Anteriq designates for the Service.
For the Customer: the Customer’s account owner, administrator, or notice contact identified in the Agreement or the Service.
For Anteriq: Anteriq, LLC, 11479 S Pine Dr, Parker, CO 80134, or any privacy or security contact Anteriq designates for the Service.
- Section 16.1 does not apply to the service of any proceedings or other documents in any legal action or, where applicable, any arbitration or other method of dispute resolution.
signature page follows
The parties may, but are not required to, execute this DPA. This DPA is effective and binding as of the effective date set forth above upon the Customer’s acceptance of the Agreement or its access to or use of the Service after this DPA is made available, whether or not signed below. Where the parties elect to execute this DPA, they do so as of the effective date set forth above.
Customer By_________________ Name: Title:
Anteriq, LLC By_________________ Name: Title:
APPENDIX A
Customer Personal Data Processing Purposes and Details
Business Purposes: Providing the Customer with access to, and use of, Anteriq’s U.S.-based cloud SaaS practice-management and client-operations platform for financial planning firms and related services, including user account administration, customer onboarding, client and household management, workflow and task management, document and data organization, collaboration features, integrations enabled by the Customer, support, maintenance, security, troubleshooting, analytics, and service improvement.
Customer Personal Data Categories: Business contact information; user account and profile information; login and authentication data; Customer-submitted content associated with financial planning practice management, end-client operations, client records, financial profile information, meeting notes, workflows, tasks, communications, documents, integrations enabled by the Customer, support requests, device, usage, and log data; and any other Customer Personal Data the Customer submits to the Service or instructs Anteriq to process. The Customer, as the controller, business, financial institution, or equivalent responsible party, determines the categories of Customer Personal Data (including end-client data) submitted to the Service and remains responsible for such data and for its compliance obligations with respect to it, as set out in Section 2.1; Anteriq processes such data solely as a service provider or processor on the Customer’s behalf.
Data Subject Types: The Customer’s employees, contractors, agents, advisors, representatives, end-clients, prospective clients, client household members, vendors, service providers, and other individuals whose Customer Personal Data is submitted to or made available through the Service by or on behalf of the Customer.
Processing Duration: For the duration of the Agreement and for any additional period during which Anteriq retains Customer Personal Data in accordance with this DPA.
Approved Subprocessors: As identified by Anteriq through the Service, its website, or another reasonable electronic method made available to the Customer.
Anteriq may update the approved subprocessor list in accordance with the 30-day notice and objection process in this DPA for subprocessors that Anteriq engages to provide the core Service. This notice and objection process does not apply to optional subprocessors, integrations, or third-party services that the Customer elects to enable or disable at its own discretion through the Service, which the Customer may choose not to use.
Locations where Anteriq may receive, access, process, or store Customer Personal Data: United States only, unless separately agreed in writing by Anteriq and the Customer. This location commitment applies to Anteriq’s own processing of Customer Personal Data. Anteriq’s subprocessors operate their own infrastructure under their own regional practices, and this Appendix does not state where a subprocessor processes data, as described in Section 7.1.
Appendix B
Security Measures
Anteriq will maintain administrative, technical, and physical safeguards designed to protect Customer Personal Data appropriate to the nature of Customer Personal Data and the risks presented by the processing, including the following measures. Anteriq also maintains a separate Security Exhibit describing its then-current infrastructure, logging, backup, and monitoring controls in greater detail, which is incorporated into this DPA by reference. The measures in this Appendix B state Anteriq’s baseline commitments; the Security Exhibit provides supplemental detail, and in the event of any conflict between the two, the measures set out in this Appendix B control. Anteriq may update the Security Exhibit from time to time provided that the updated controls afford a level of protection no less protective of Customer Personal Data than those described in this Appendix B.
-
Physical access controls for offices and facilities used to support the Service, including visitor controls and restricted access where appropriate.
-
System access controls, including unique user IDs, strong authentication measures, role-based access, and periodic access review.
-
Data access controls designed to limit access to Customer Personal Data to authorized personnel with a legitimate business need to know.
-
Transmission controls, including encryption of Customer Personal Data in transit using industry-standard protocols where appropriate.
-
Input and change controls, including logging and monitoring of administrative access and material system activity where appropriate.
-
Data backup and restoration procedures designed to support availability and recovery of Customer Personal Data.
-
Backup and recovery, including a continuous point-in-time recovery window and scheduled backups written to a write-once (immutable) vault, with backup recovery points that cannot be modified or deleted before their retention period expires. Recovery procedures are maintained in an operational runbook and a restore is exercised at least annually in a non-production environment. Retention and deletion of backup copies are governed by Section 11 of this DPA and Anteriq’s data retention and deletion practices.
-
Data segregation, secure configuration, vulnerability management, and other measures reasonably designed to protect Customer Personal Data within a multi-tenant software environment.