Data Processing Agreement
This Data Processing Addendum, including its schedules and any applicable transfer terms (the “DPA”), forms part of the agreement governing Customer’s access to and use of the Services (the “Agreement”) between the customer identified in the Agreement (“Customer”) and Umami Software, Inc., 28 Geary St, Suite 650 #243, San Francisco, California, United States (“Umami”).
Acceptance and effective date
This DPA is incorporated into the Agreement by reference and applies automatically when Umami processes Customer Personal Data on Customer’s behalf in connection with the Services.
By entering into the Agreement, creating or using an account under the Agreement, submitting an order for the Services, or otherwise electronically accepting the Agreement, Customer enters into and agrees to this DPA on behalf of itself and any Customer Affiliates authorized to use the Services.
This DPA is legally binding on the parties without a handwritten, electronic, or countersignature. The parties agree that Customer’s electronic acceptance of the Agreement, together with Umami’s provision of the Services, constitutes execution of this DPA. Electronic records maintained in the ordinary course of business may be used to establish acceptance, the applicable version, and the effective date.
The “Effective Date” of this DPA is the date on which the Agreement becomes effective for Customer or, for an existing Customer, the date on which this version of the DPA becomes effective under the Agreement.
A separately signed copy is not required. If the parties execute a separate written agreement that expressly supersedes this DPA, that separate agreement controls to the extent of the conflict.
1. Definitions
1.1 Defined terms
In this DPA:
“Affiliate” means an entity that directly or indirectly controls, is controlled by, or is under common control with a party.
“Applicable Data Protection Law” means any law or regulation applicable to Umami’s Processing of Customer Personal Data under the Agreement, including, where applicable:
- Regulation (EU) 2016/679 (“EU GDPR”);
- the EU GDPR as incorporated into United Kingdom law, together with the UK Data Protection Act 2018 (“UK Data Protection Law”);
- the Swiss Federal Act on Data Protection (“Swiss FADP”); and
- applicable United States state privacy laws that impose obligations on a processor, service provider, or contractor with respect to Customer Personal Data.
“Customer Affiliate” means an Affiliate of Customer that is permitted to use the Services under the Agreement and for which Umami Processes Customer Personal Data.
“Customer Personal Data” means Personal Data that Umami Processes on behalf of Customer in connection with the Services. Customer Personal Data does not include Personal Data for which Umami determines the purposes and means of Processing, such as account administration, billing, direct customer communications, security, fraud prevention, and Umami’s own legal compliance, which is governed by Umami’s Privacy Policy.
“Data Subject Request” means a request by a Data Subject to exercise a right under Applicable Data Protection Law.
“EU SCCs” means the standard contractual clauses for transfers of Personal Data to third countries adopted by the European Commission in Implementing Decision (EU) 2021/914 dated June 4, 2021.
“Personal Data”, “Process”, “Processing”, “Controller”, “Processor”, “Data Subject”, “Supervisory Authority”, and “Personal Data Breach” have the meanings given to them under Applicable Data Protection Law. Where a United States state privacy law applies, these terms include the corresponding concepts under that law.
“Restricted Transfer” means a transfer of Customer Personal Data that requires an approved transfer mechanism under Applicable Data Protection Law.
“Security Incident” means a confirmed Personal Data Breach affecting Customer Personal Data. Security Incident does not include unsuccessful attempts or activities that do not compromise Customer Personal Data, including unsuccessful login attempts, port scans, denial-of-service attempts, pings, or other attacks that do not result in unauthorized access to Customer Personal Data.
“Services” means Umami’s hosted cloud services, support services, and related services provided to Customer under the Agreement.
“Subprocessor” means a third party appointed by or on behalf of Umami to Process Customer Personal Data in connection with the Services.
“UK Addendum” means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner under section 119A of the UK Data Protection Act 2018, as revised or replaced from time to time.
1.2 Scope
This DPA applies only to the extent Umami Processes Customer Personal Data as a Processor or Subprocessor on Customer’s behalf.
This DPA does not apply to:
- Customer’s use of self-hosted or open-source Umami software where Umami does not receive or Process the relevant data;
- data that has been irreversibly anonymized so that it is no longer Personal Data; or
- Processing for which Umami acts independently as a Controller, as described in Umami’s Privacy Policy.
2. Roles and instructions
2.1 Roles of the parties
As between the parties:
- Customer is the Controller of Customer Personal Data and Umami is its Processor; or
- where Customer Processes Personal Data on behalf of another Controller, Customer is a Processor and Umami is Customer’s Subprocessor.
Each party will comply with the obligations applicable to it under Applicable Data Protection Law.
2.2 Customer instructions
Customer instructs Umami to Process Customer Personal Data:
- to provide, maintain, secure, support, and improve the Services;
- as configured or initiated by Customer and its authorized users through their use of the Services;
- as described in the Agreement and this DPA; and
- as otherwise documented in writing and agreed by Umami.
The Agreement, this DPA, Customer’s configuration and use of the Services, and support requests submitted by authorized users constitute Customer’s documented instructions.
2.3 Legally required Processing
Umami will not Process Customer Personal Data other than on Customer’s documented instructions unless applicable law requires otherwise. If law requires other Processing, Umami will inform Customer before the Processing unless the law prohibits that notice on important grounds of public interest.
If Umami reasonably believes an instruction violates Applicable Data Protection Law, Umami will notify Customer and may suspend the affected Processing until the parties resolve the issue.
2.4 Customer responsibilities
Customer is responsible for:
- the lawfulness, fairness, transparency, and accuracy of Customer Personal Data and Customer’s Processing instructions;
- providing all notices and obtaining all consents or other legal bases required for Customer’s use of the Services;
- configuring and using the Services in compliance with Applicable Data Protection Law;
- responding to Data Subject Requests, except for the assistance Umami must provide under this DPA; and
- ensuring that Customer does not instruct Umami to Process data in violation of the Agreement or applicable law.
Customer will not submit to the Services any special categories of Personal Data under Article 9 of the EU GDPR, data relating to criminal convictions and offences, protected health information, payment-card data, government identification numbers, or other highly sensitive regulated data unless the Agreement expressly permits that data and the parties have agreed in writing to any additional safeguards required.
3. Processing obligations
3.1 Purpose limitation
Umami will Process Customer Personal Data only for the limited and specified purposes described in the Agreement, this DPA, and Customer’s documented instructions.
Umami will not sell Customer Personal Data, share Customer Personal Data for cross-context behavioral advertising, or retain, use, or disclose Customer Personal Data outside the direct business relationship between Umami and Customer except as permitted by Applicable Data Protection Law and the Agreement.
3.2 Confidentiality
Umami will ensure that personnel authorized to Process Customer Personal Data:
- are subject to appropriate confidentiality obligations;
- receive access only as necessary to perform their duties; and
- Process Customer Personal Data only as permitted by the Agreement, this DPA, and applicable law.
3.3 Details of Processing
The subject matter, duration, nature, purpose, types of Personal Data, and categories of Data Subjects are described in Schedule 1.
4. Security
4.1 Security measures
Taking into account the state of the art, implementation costs, the nature, scope, context, and purposes of Processing, and the risks to Data Subjects, Umami will implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access.
The measures in effect as of the Effective Date are described in Schedule 2 and on Umami’s security page. Umami may update its security measures from time to time, provided that the updates do not materially reduce the overall protection of Customer Personal Data during the applicable subscription term.
4.2 Customer security responsibilities
Customer is responsible for appropriately configuring the Services, protecting account credentials and authentication methods, controlling access by Customer personnel, and using available security features in a manner appropriate to the nature of Customer Personal Data.
5. Security Incidents
5.1 Notification
Umami will notify Customer without undue delay after becoming aware of a Security Incident.
Notification will be delivered to Customer’s account administrator, security contact, or another contact designated by Customer. Customer is responsible for keeping its contact information current.
5.2 Information and cooperation
To the extent known and reasonably available, Umami’s notification will describe:
- the nature of the Security Incident;
- the categories and approximate number of affected Data Subjects and records;
- the likely consequences;
- the measures taken or proposed to address and mitigate the Security Incident; and
- a contact point for follow-up.
Umami may provide information in phases as it becomes available. Umami will take reasonable steps to contain, investigate, mitigate, and remediate the Security Incident and will reasonably assist Customer with Customer’s legally required notifications.
Notification or assistance under this section is not an admission of fault or liability.
6. Assistance to Customer
6.1 Data Subject Requests
Taking into account the nature of the Processing, Umami will provide reasonable assistance through appropriate technical and organizational measures to help Customer respond to Data Subject Requests.
If Umami receives a Data Subject Request relating to Customer Personal Data, Umami will:
- promptly notify Customer where reasonably able to identify the relevant Customer;
- not respond on Customer’s behalf unless Customer authorizes Umami to do so or applicable law requires a response; and
- where appropriate, direct the Data Subject to Customer.
6.2 Compliance assistance
Taking into account the nature of the Processing and the information available to Umami, Umami will provide reasonable assistance with:
- Customer’s security obligations;
- Personal Data Breach notifications;
- data protection impact assessments; and
- prior consultations with Supervisory Authorities.
Umami may charge reasonable fees for unusually burdensome or repetitive assistance not included in the Services, except to the extent the request results from Umami’s breach of this DPA.
7. Subprocessors
7.1 General authorization
Customer provides general written authorization for Umami to appoint Subprocessors in accordance with this section.
Umami’s current Subprocessors are listed at:
https://umami.is/subprocessors
Customer authorizes the Subprocessors listed there as of the Effective Date.
7.2 Subprocessor obligations
Before a Subprocessor Processes Customer Personal Data, Umami will enter into a written agreement requiring the Subprocessor to provide data protection obligations that are no less protective in substance than those applicable to Umami under this DPA, to the extent relevant to the services performed by that Subprocessor.
Umami remains responsible for the performance of its Subprocessors’ obligations to the extent required by Applicable Data Protection Law.
7.3 Notice of changes
Umami will provide at least fifteen (15) days’ advance notice before authorizing a new Subprocessor to Process Customer Personal Data, except where an urgent change is reasonably necessary to maintain the availability, security, or legal compliance of the Services. Notice may be provided by email, an in-product notice, or another reasonable electronic method. For an urgent change, Umami will provide notice as soon as reasonably practicable.
Umami may provide a mechanism for Customer to subscribe to Subprocessor notices. Customer is responsible for maintaining a current notification address and subscribing where that mechanism is offered.
7.4 Objections
Customer may object to a new Subprocessor by sending Umami a written objection within ten (10) days after receiving notice. The objection must explain the reasonable, documented data-protection grounds for the objection.
The parties will work in good faith to resolve a valid objection. Umami may, at its option:
- not use the Subprocessor for Customer Personal Data;
- offer a commercially reasonable configuration or alternative that avoids the affected Processing; or
- permit Customer to terminate the affected portion of the Services.
If no commercially reasonable resolution is available, either party may terminate the affected Services. Umami will refund prepaid fees covering the terminated Services after the effective termination date. This termination right is Customer’s sole and exclusive remedy for an unresolved Subprocessor objection.
8. Return and deletion
8.1 During the term
Customer may access, retrieve, or delete Customer Personal Data using the features of the Services, subject to the Agreement.
8.2 Following termination
Upon termination or expiration of the Services, and at Customer’s choice where required by Applicable Data Protection Law, Umami will delete or return Customer Personal Data in accordance with the Agreement and the functionality of the Services, unless applicable law requires continued retention.
Customer must export any Customer Personal Data it wishes to retain before the end of any retrieval period provided under the Agreement.
8.3 Backups and legal retention
Customer Personal Data remaining in backups, archives, or disaster-recovery systems will be protected under this DPA, isolated from ordinary use, and deleted in accordance with Umami’s ordinary retention and backup cycles, unless law requires longer retention.
Where law requires retention, Umami will continue to protect the retained data and will Process it only for the legally required purpose.
9. Information and audit rights
9.1 Compliance information
Upon reasonable written request, Umami will make available information reasonably necessary to demonstrate compliance with this DPA. Umami may satisfy this obligation by providing relevant documentation, policies, security summaries, questionnaires, third-party reports, certifications, or audit reports then available.
9.2 Audits
If the information provided under Section 9.1 is not reasonably sufficient to demonstrate compliance, Customer may request an audit as required by Applicable Data Protection Law.
Unless a Supervisory Authority requires otherwise or Customer reasonably believes a Security Incident or material breach has occurred, an audit must:
- occur no more than once in any twelve-month period;
- be requested on at least thirty (30) days’ written notice;
- occur during normal business hours;
- avoid unreasonable disruption to Umami’s business;
- be limited to systems, records, and personnel relevant to Customer Personal Data;
- not provide access to another customer’s data or Umami’s confidential or security-sensitive information; and
- be conducted by Customer or an independent auditor that is not a competitor of Umami and is bound by confidentiality obligations acceptable to Umami.
Before an onsite audit, the parties will agree on scope, timing, duration, security, confidentiality, and reimbursement of reasonable costs.
Customer will bear its audit costs and reimburse Umami for reasonable costs incurred in supporting the audit, except where the audit identifies a material breach of this DPA by Umami.
10. International transfers
10.1 Transfer mechanisms
Umami will not make a Restricted Transfer unless the transfer is supported by a legally valid transfer mechanism, which may include:
- an applicable adequacy decision;
- the EU SCCs;
- the UK Addendum;
- another approved contractual mechanism; or
- another lawful basis permitted by Applicable Data Protection Law.
10.2 EU transfers
Where Customer Personal Data protected by the EU GDPR is transferred to Umami in a country that has not been recognized as providing an adequate level of protection, the EU SCCs are incorporated into this DPA and apply as described in Schedule 3.
10.3 United Kingdom transfers
Where Customer Personal Data protected by UK Data Protection Law is subject to a Restricted Transfer, the UK Addendum is incorporated into this DPA, the EU SCCs are modified by the UK Addendum, and the tables of the UK Addendum are deemed completed using the information in the Agreement and Schedules 1 through 3.
10.4 Switzerland transfers
Where Customer Personal Data protected by the Swiss FADP is subject to a Restricted Transfer:
- the EU SCCs apply with references to the EU GDPR interpreted to include the Swiss FADP;
- references to the European Union, Member States, and competent Supervisory Authorities will be interpreted to include Switzerland and the Swiss Federal Data Protection and Information Commissioner where applicable;
- Data Subjects in Switzerland may enforce their rights under the EU SCCs; and
- the EU SCCs will be interpreted to provide the level of protection required by the Swiss FADP.
10.5 Transfer assessments and supplementary measures
Upon reasonable request, Umami will provide information reasonably available to it that Customer needs to conduct a legally required transfer assessment. Each party will comply with its obligations under the applicable transfer mechanism.
If a competent authority determines that the selected transfer mechanism is invalid or insufficient, the parties will cooperate in good faith to implement an alternative valid mechanism.
11. United States state privacy laws
To the extent a United States state privacy law applies to Umami’s Processing of Customer Personal Data, Umami will act as Customer’s processor, service provider, or contractor, as applicable.
Umami will:
- Process Customer Personal Data only for the limited and specified purposes described in the Agreement, this DPA, and Customer’s documented instructions;
- not sell Customer Personal Data;
- not share Customer Personal Data for cross-context behavioral advertising or targeted advertising as those terms are defined by applicable law;
- not retain, use, or disclose Customer Personal Data outside the direct business relationship with Customer or for a commercial purpose other than providing the Services, except as permitted by law;
- not combine Customer Personal Data with Personal Data received from another person or collected through Umami’s independent interactions with a consumer, except as permitted by law;
- provide the same level of privacy protection required of Customer to the extent applicable to Umami’s role;
- notify Customer if Umami determines it can no longer meet an applicable obligation; and
- allow Customer to take reasonable and appropriate steps to stop and remediate unauthorized use of Customer Personal Data.
Customer may exercise its monitoring rights through the information and audit procedures in Section 9.
12. Customer Affiliates
Customer enters into this DPA on behalf of each Customer Affiliate permitted to use the Services, unless that Customer Affiliate has entered into its own agreement with Umami.
Each Customer Affiliate may exercise rights under this DPA only through Customer, except where Applicable Data Protection Law requires otherwise. Customer is responsible for coordinating all communications, instructions, requests, and claims on behalf of Customer Affiliates.
13. Liability
The exclusions and limitations of liability in the Agreement apply to this DPA and the EU SCCs to the maximum extent permitted by applicable law.
Any liability arising under this DPA is aggregated with, and not in addition to, liability arising under the Agreement. Nothing in this section limits rights that cannot lawfully be limited, including rights granted directly to Data Subjects under the EU SCCs.
14. Term, precedence, and updates
14.1 Term
This DPA remains in effect for as long as Umami Processes Customer Personal Data on Customer’s behalf.
14.2 Order of precedence
If there is a conflict:
- the EU SCCs or UK Addendum control with respect to the Restricted Transfer they govern;
- this DPA controls over the Agreement with respect to the Processing of Customer Personal Data; and
- the Agreement controls for all other matters.
Nothing in this DPA varies or modifies the EU SCCs in a manner that reduces the rights or protections granted by them.
14.3 Governing law
Except where the EU SCCs, UK Addendum, or Applicable Data Protection Law requires otherwise, this DPA is governed by the governing-law and dispute-resolution provisions of the Agreement.
14.4 Updates
Umami may update this DPA as permitted by the Agreement to reflect changes in law, regulation, regulatory guidance, or the Services. Umami will provide notice of material updates as required by the Agreement and will not materially reduce the overall protection of Customer Personal Data during a paid subscription term except where necessary to comply with applicable law.
Archived versions should be made available or retained by Umami so the version applicable on a given date can be identified.
15. Notices and contact
Notices under this DPA must be provided in writing.
Notices to Customer may be sent to the account owner, administrator, legal, privacy, or security contact associated with Customer’s account.
Notices to Umami concerning this DPA should be sent to:
Umami Software, Inc.
28 Geary St, Suite 650 #243
San Francisco, California
United States
Email: [email protected]
SCHEDULE 1
DETAILS OF PROCESSING
1. Subject matter
Umami’s Processing of Customer Personal Data as necessary to provide, maintain, secure, support, and improve the Services under the Agreement.
2. Duration
The term of the Agreement and any period after termination during which Umami Processes Customer Personal Data in accordance with the Agreement, this DPA, or applicable law.
3. Nature and purpose
Depending on Customer’s configuration and enabled features, Processing may include:
- collecting analytics and event data from Customer’s websites, applications, links, pixels, or other properties;
- hosting, storing, organizing, aggregating, querying, displaying, and exporting analytics data;
- providing dashboards, reports, funnels, journeys, cohorts, retention analysis, heatmaps, session-related functionality, and similar analytics features;
- authenticating users and administering access;
- providing customer support, troubleshooting, maintenance, monitoring, security, abuse prevention, and incident response;
- backing up and recovering the Services; and
- complying with Customer’s documented instructions and applicable law.
4. Categories of Data Subjects
Depending on Customer’s use of the Services:
- visitors and users of Customer’s websites, applications, or other properties;
- Customer’s customers, prospects, end users, employees, contractors, and other personnel;
- users authorized by Customer to access the Services; and
- individuals whose Personal Data Customer submits to or collects through the Services.
5. Types of Personal Data
Depending on Customer’s configuration and enabled features:
- website, application, page, screen, link, and event information;
- URLs, page titles, referrers, campaign parameters, and search parameters;
- timestamps and approximate session or visit information;
- browser, operating-system, device, language, screen, and similar technical metadata;
- network information processed transiently to provide security, routing, or approximate location functionality;
- country, region, city, or other approximate location information;
- custom events, event properties, tags, identifiers, and metadata submitted by Customer;
- session, interaction, heatmap, or replay-related information where the applicable feature is enabled;
- account identifiers, user names, email addresses, roles, permissions, and audit information for Customer’s authorized users; and
- support communications and diagnostic information submitted by Customer.
Customer controls the data it submits or configures the Services to collect. Customer must not use custom fields or event properties to submit prohibited or unnecessary Personal Data.
6. Special categories of Personal Data
None intended. Customer is prohibited from submitting special-category or similarly sensitive regulated data unless expressly permitted by the Agreement and agreed in writing by Umami.
7. Frequency
Continuous or as initiated by Customer and its authorized users during the term of the Agreement.
8. Retention
As configured by Customer, described in the Agreement or applicable product documentation, required to provide the Services, or required by law. Following termination, Section 8 of this DPA applies.
9. Subprocessors
The current list is maintained at:
https://umami.is/subprocessors
SCHEDULE 2
TECHNICAL AND ORGANIZATIONAL MEASURES
Umami maintains a security program appropriate to the nature of the Services and Customer Personal Data. Measures may include the following, as appropriate to the relevant systems and risks.
1. Information-security governance
- documented security responsibilities and operational procedures;
- assignment of responsibility for security and incident handling;
- periodic assessment and improvement of security controls; and
- confidentiality obligations for personnel with access to Customer Personal Data.
2. Access control
- access limited according to role, job responsibility, and least-privilege principles;
- authentication controls for systems Processing Customer Personal Data;
- multi-factor authentication for privileged or administrative access where technically supported;
- procedures for granting, changing, reviewing, and revoking access; and
- logging or review of material administrative access where appropriate.
3. Encryption and transmission security
- encryption of Customer Personal Data in transit using industry-standard transport encryption;
- encryption at rest where supported by Umami’s infrastructure and storage providers;
- secure management of credentials, secrets, and encryption material; and
- measures designed to prevent unauthorized interception or disclosure.
4. Application and infrastructure security
- secure configuration of production infrastructure;
- logical separation of environments and customer data as appropriate;
- vulnerability monitoring, dependency review, updates, and security patching;
- controls designed to mitigate common web-application and infrastructure threats;
- change-management and deployment procedures; and
- protections against abuse, malicious traffic, and unauthorized access.
5. Availability, backup, and recovery
- monitoring of production availability and material operational events;
- backup or recovery measures appropriate to the Services;
- procedures designed to restore availability following an incident; and
- capacity, redundancy, and resilience measures appropriate to the Services and service tier.
6. Logging and monitoring
- operational logging and monitoring appropriate to production systems;
- alerting and investigation procedures for suspected security events;
- restricted access to logs containing Personal Data; and
- retention of security and operational logs for periods appropriate to their purpose.
7. Incident response
- procedures to identify, investigate, contain, mitigate, and remediate Security Incidents;
- internal escalation and communication procedures;
- preservation of relevant evidence where appropriate; and
- post-incident review and corrective action where appropriate.
8. Data minimization and lifecycle controls
- collection and Processing limited to data required for the Services and Customer’s configuration;
- customer controls for configuration, access, export, or deletion where supported;
- retention and deletion procedures; and
- restrictions on production data use in development or testing except where appropriately protected.
9. Personnel security
- security and privacy awareness appropriate to personnel roles;
- confidentiality obligations;
- access removal following termination or role change; and
- screening or additional controls for sensitive roles where appropriate and legally permitted.
10. Supplier management
- assessment of Subprocessors appropriate to the nature and risk of their services;
- written data-protection and confidentiality obligations;
- review of material security or compliance information where available; and
- ongoing management of Subprocessor changes under Section 7.
Current public security information may be maintained at:
https://umami.is/security
SCHEDULE 3
EU STANDARD CONTRACTUAL CLAUSES
Where the EU SCCs apply under Section 10, they are incorporated into this DPA as follows.
1. Applicable modules
- Module Two — Controller to Processor applies where Customer is a Controller and Umami is a Processor.
- Module Three — Processor to Processor applies where Customer is a Processor and Umami is a Subprocessor.
Where both relationships apply, the appropriate module applies to each transfer.
2. Clause selections
- Clause 7, the docking clause, applies.
- In Clause 9, Option 2, general written authorization, applies. The notice period is the period specified in Section 7.3 of this DPA.
- The optional language in Clause 11 does not apply.
- In Clause 17, Option 1 applies, and the EU SCCs are governed by the law of Ireland.
- Under Clause 18, disputes will be resolved by the courts of Ireland.
3. Annex I.A — List of parties
Data exporter
The Customer identified in the Agreement.
- Address: The address associated with Customer’s account, order form, or other Agreement record.
- Contact details: Customer’s account owner, administrator, privacy contact, or other contact specified in the Agreement.
- Activities relevant to the transfer: Customer’s use of the Services as described in the Agreement and Schedule 1.
- Role: Controller under Module Two or Processor under Module Three.
Data importer
- Name: Umami Software, Inc.
- Address: 28 Geary St, Suite 650 #243, San Francisco, California, United States
- Contact details: [email protected]
- Activities relevant to the transfer: Provision of the Services as described in the Agreement and Schedule 1.
- Role: Processor under Module Two or Subprocessor under Module Three.
The parties are deemed to have signed Annex I.A through their execution or electronic acceptance of the Agreement and this DPA on the Effective Date. No additional signature is required.
4. Annex I.B — Description of transfer
The categories of Data Subjects, categories of Personal Data, frequency, nature, purpose, duration, and retention period are described in Schedule 1.
For transfers to Subprocessors, the subject matter, nature, and duration of Processing correspond to the services provided by the relevant Subprocessor as identified on Umami’s Subprocessor list.
5. Annex I.C — Competent Supervisory Authority
The competent Supervisory Authority is determined in accordance with Clause 13 of the EU SCCs.
6. Annex II — Security measures
The technical and organizational measures are described in Schedule 2.
7. Annex III — Subprocessors
For Module Three, the authorized Subprocessors are identified at:
https://umami.is/subprocessors
The parties agree that the Subprocessor list, together with the information in the Agreement and Schedules 1 and 2, completes Annex III.
Last updated August 2, 2026