This Data Processing Addendum (“DPA”) supplements the Master Services and Equipment Agreement (the “Agreement”) entered into by and between Customer and Mashgin, Inc (henceforth “Mashgin”). By entering into the Agreement, when required by applicable Data Protection Laws (defined below), Customer enters into this DPA on behalf of itself and on behalf of its Affiliates (defined below), if any. This DPA incorporates the terms of the Agreement, and any terms not defined in this DPA shall have the meaning set forth in the Agreement.
1. Definitions
1.1 “Affiliate” means (i) an entity of which a party directly or indirectly owns fifty percent (50%) or more of the stock or other equity interest, (ii) an entity that owns at least fifty percent (50%) or more of the stock or other equity interest of a party, or (iii) an entity which is under common control with a party by having at least fifty percent (50%) or more of the stock or other equity interest of such entity and a party owned by the same person, but such entity shall only be deemed to be an Affiliate so long as such ownership exists.
1.2 “Authorized Sub-Processor” means a third-party who has a need to know or otherwise access Customer’s Personal Data to enable Mashgin to perform its obligations under this DPA or the Agreement, and who is either (1) listed in Exhibit B or (2) subsequently authorized under Section 4.2 of this DPA.
1.3 “Data Exporter” means Customer.
1.4 “Data Importer” means Mashgin.
1.5 “Data Protection Laws” means any applicable laws and regulations in any relevant jurisdiction relating to the use or processing of Personal Data including: (i) the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 (“CCPA”), (ii) the General Data Protection Regulation (Regulation (EU) 2016/679) (“EU GDPR”) and the EU GDPR as it forms part of the law of England and Wales by virtue of section 3 of the European Union (Withdrawal) Act 2018 (the “UK GDPR”) (together, collectively, the “GDPR”), (iii) the Swiss Federal Act on Data Protection, (iv) the UK Data Protection Act 2018, (v) the Privacy and Electronic Communications (EC Directive) Regulations 2003, (vi) the Virginia Consumer Data Protection Act (“VCDPA”), (vii) the Colorado Privacy Act (“CPA”), (viii) the Connecticut Data Privacy Act (“CTDPA”), (ix) the Utah Consumer Privacy Act (“UCPA”); and (x) the Washington My Health My Data Act (“MHMDA”), in each case, as updated, amended or replaced from time to time. The terms “Data Subject”, “Personal Data”, “Personal Data Breach”, “processing”, “processor,” “controller,” and “supervisory authority” shall have the meanings set forth in the GDPR.
1.6 “EU SCCs” means the standard contractual clauses approved by the European Commission in Commission Decision 2021/914 dated 4 June 2021, for transfers of personal data to countries not otherwise recognized as offering an adequate level of protection for personal data by the European Commission (as amended and updated from time to time), as modified by Section 6.2 of this DPA.
1.7 “ex-EEA Transfer” means the transfer of Personal Data, which is processed in accordance with the GDPR, from the Data Exporter to the Data Importer (or its premises) outside the European Economic Area (the “EEA”), and such transfer is not governed by an adequacy decision made by the European Commission in accordance with the relevant provisions of the GDPR.
1.8 “ex-UK Transfer” means the transfer of Personal Data covered by Chapter V of the UK GDPR, which is processed in accordance with the UK GDPR and the Data Protection Act 2018, from the Data Exporter to the Data Importer (or its premises) outside the United Kingdom (the “UK”), and such transfer is not governed by an adequacy decision made by the Secretary of State in accordance with the relevant provisions of the UK GDPR and the Data Protection Act 2018.
1.9 “Mashgin Account Data” means personal data that relates to Mashgin’s relationship with Customer, including the names or contact information of individuals authorized by Customer to access Customer’s account and billing information of individuals that Customer has associated with its account. Mashgin Account Data also includes any data Mashgin may need to collect for the purpose of managing its relationship with Customer, identity verification, or as otherwise required by applicable laws and regulations.
1.10 “Mashgin Usage Data” means Service usage data collected and processed by Mashgin in connection with the provision of the Services, including without limitation data used to identify the source and destination of a communication, activity logs, and data used to optimize and maintain performance of the Services, and to investigate and prevent system abuse.
1.11 “Services” shall have the meaning set forth in the Agreement.
1.12 “Standard Contractual Clauses” means the EU SCCs and the UK SCCs.
1.13 “UK Addendum” has the meaning set forth in Exhibit D.
1.14 “UK SCCs” means the EU SCCs, as amended by the UK Addendum.
2. Relationship of the Parties; Processing of Data
2.1 The parties acknowledge and agree that with regard to the processing of Personal Data, Customer may act either as a controller or processor and, except as expressly set forth in this DPA or the Agreement, Mashgin is a processor. Customer shall, in its use of the Services, at all times process Personal Data, and provide instructions for the processing of Personal Data, in compliance with Data Protection Laws. Customer shall ensure that the processing of Personal Data in accordance with Customer’s instructions will not cause Mashgin to be in breach of the Data Protection Laws. Customer is solely responsible for the accuracy, quality, and legality of (i) the Personal Data provided to Mashgin by or on behalf of Customer, (ii) the means by which Customer acquired any such Personal Data, and (iii) the instructions it provides to Mashgin regarding the processing of such Personal Data. Customer shall not provide or make available to Mashgin any Personal Data in violation of the Agreement or otherwise inappropriate for the nature of the Services, and shall indemnify Mashgin from all claims and losses in connection therewith.
2.2 Mashgin shall not process Personal Data (i) for purposes other than those set forth in the Agreement and/or Exhibit A, (ii) in a manner inconsistent with the terms and conditions set forth in this DPA or any other documented instructions provided by Customer, including with regard to transfers of personal data to a third country or an international organization, unless required to do so by Supervisory Authority to which Mashgin is subject; in such a case, Mashgin shall inform the Customer of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest, or (iii) in violation of Data Protection Laws. Customer hereby instructs Mashgin to process Personal Data in accordance with the foregoing and as part of any processing initiated by Customer in its use of the Services.
2.3 The subject matter, nature, purpose, and duration of this processing, as well as the types of Personal Data collected and categories of Data Subjects, are described in Exhibit A to this DPA.
2.4 Following completion of the Services, at Customer’s choice, Mashgin shall return or delete Customer’s Personal Data, unless further storage of such Personal Data is required or authorized by applicable law. If return or destruction is impracticable or prohibited by law, rule or regulation, Mashgin shall take measures to block such Personal Data from any further processing (except to the extent necessary for its continued hosting or processing required by law, rule or regulation) and shall continue to appropriately protect the Personal Data remaining in its possession, custody, or control. If Customer and Mashgin have entered into Standard Contractual Clauses as described in Section 6 (Transfers of Personal Data), the parties agree that the certification of deletion of Personal Data that is described in Clause 8.1(d) and Clause 8.5 of the EU SCCs (as applicable) shall be provided by Mashgin to Customer only upon Customer’s request.
2.5 The Parties acknowledge and agree that the processing of personal information or personal data that is subject to the CCPA, VCDPA, CPA, CTDPA, UCPA, or MHMDA shall be carried out in accordance with the terms set forth in Exhibit E.
3. Confidentiality
Mashgin shall ensure that any person it authorizes to process Personal Data has agreed to protect Personal Data in accordance with Mashgin’s confidentiality obligations in the Agreement. Customer agrees that Mashgin may disclose Personal Data to its advisers, auditors or other third parties as reasonably required in connection with the performance of its obligations under this DPA, the Agreement, or the provision of Services to Customer.
4. Authorized Sub-Processors
4.1 Customer acknowledges and agrees that Mashgin may (1) engage its Affiliates and the Authorized Sub-Processors listed in Exhibit B to this DPA to access and process Personal Data in connection with the Services and (2) from time to time engage additional third parties for the purpose of providing the Services, including without limitation the processing of Personal Data. By way of this DPA, Customer provides general written authorization to Mashgin to engage sub-processors as necessary to perform the Services.
4.2 A list of Mashgin’s current Authorized Sub-Processors (the “List”) will be made available to Customer, either attached hereto, at a link provided to Customer, via email or through another means made available to Customer. Such List may be updated by Mashgin from time to time. Mashgin may provide a mechanism to subscribe to notifications of new Authorized Sub-Processors and Customer agrees to subscribe to such notifications where available. At least ten (10) days before enabling any third party other than existing Authorized Sub-Processors to access or participate in the processing of Personal Data, Mashgin will add such third party to the List and notify Customer via email. Customer may object to such an engagement by informing Mashgin within ten (10) days of receipt of the aforementioned notice by Customer, provided such objection is in writing and based on reasonable grounds relating to data protection. Customer acknowledges that certain sub-processors are essential to providing the Services and that objecting to the use of a sub-processor may prevent Mashgin from offering the Services to Customer.
4.3 If Customer reasonably objects to an engagement in accordance with Section 4.2, and Mashgin cannot provide a commercially reasonable alternative within a reasonable period of time, Customer may discontinue the use of the affected Service by providing written notice to Mashgin. Discontinuation shall not relieve Customer of any fees owed to Mashgin under the Agreement.
4.4 If Customer does not object to the engagement of a third party in accordance with Section 4.2 within ten (10) days of notice by Mashgin, that third party will be deemed an Authorized Sub-Processor for the purposes of this DPA.
4.5 Mashgin will enter into a written agreement with the Authorized Sub-Processor imposing on the Authorized Sub-Processor data protection obligations comparable to those imposed on Mashgin under this DPA with respect to the protection of Personal Data. In case an Authorized Sub-Processor fails to fulfill its data protection obligations under such written agreement with Mashgin, Mashgin will remain liable to Customer for the performance of the Authorized Sub-Processor’s obligations under such agreement.
4.6 If Customer and Mashgin have entered into Standard Contractual Clauses as described in Section 6 (Transfers of Personal Data), (i) the above authorizations will constitute Customer’s prior written consent to the subcontracting by Mashgin of the processing of Personal Data if such consent is required under the Standard Contractual Clauses, and (ii) the parties agree that the copies of the agreements with Authorized Sub-Processors that must be provided by Mashgin to Customer pursuant to Clause 9(c) of the EU SCCs may have commercial information, or information unrelated to the Standard Contractual Clauses or their equivalent, removed by Mashgin beforehand, and that such copies will be provided by Mashgin only upon request by Customer.
5. Security of Personal Data.
Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, Mashgin shall maintain appropriate technical and organizational measures to ensure a level of security appropriate to the risk of processing Personal Data. Exhibit C sets forth additional information about Mashgin’s technical and organizational security measures.
6. Transfers of Personal Data
6.1 The parties agree that Mashgin may transfer Personal Data processed under this DPA outside the EEA, the UK, or Switzerland as necessary to provide the Services. Customer acknowledges that Mashgin’s primary processing operations take place in the United States, and that the transfer of Customer’s Personal Data to the United States is necessary for the provision of the Services to Customer. If Mashgin transfers Personal Data protected under this DPA to a jurisdiction for which the European Commission has not issued an adequacy decision, Mashgin will ensure that appropriate safeguards have been implemented for the transfer of Personal Data in accordance with Data Protection Laws.
6.2 Ex-EEA Transfers. The parties agree that ex-EEA Transfers are made pursuant to the EU SCCs, which are deemed entered into (and incorporated into this DPA by this reference) and completed as follows:
6.2.1 Module One (Controller to Controller) of the EU SCCs apply when Mashgin is processing Personal Data as a controller pursuant to Section 9 of this DPA.
6.2.2 Module Two (Controller to Processor) of the EU SCCs apply when Customer is a controller and Mashgin is processing Personal Data for Customer as a processor pursuant to Section 2 of this DPA.
6.2.3 Module Three (Processor to Sub-Processor) of the EU SCCs apply when Customer is a processor and Mashgin is processing Personal Data on behalf of Customer as a sub-processor.
6.3 For each module, where applicable the following applies:
6.3.1 The optional docking clause in Clause 7 does not apply;
6.3.2 In Clause 9, Option 2 (general written authorization) applies, and the minimum time period for prior notice of sub-processor changes shall be as set forth in Section 4.2 of this DPA;
6.3.3 In Clause 11, the optional language does not apply;
6.3.4 All square brackets in Clause 13 are hereby removed;
6.3.5 In Clause 17 (Option 1), the EU SCCs will be governed by Swedish law;
6.3.6 In Clause 18(b), disputes will be resolved before the courts of Stockholm, Sweden.
6.3.7 Exhibit B to this DPA contains the information required in Annex I and Annex III of the EU SCCs;
6.3.8 Exhibit C to this DPA contains the information required in Annex II of the EU SCCs; and
6.3.9 By entering into this DPA, the parties are deemed to have signed the EU SCCs incorporated herein, including their Annexes.
6.4 Ex-UK Transfers. The parties agree that ex-UK Transfers are made pursuant to the UK SCCs, which are deemed entered into and incorporated into this DPA by reference, and amended and completed in accordance with the UK Addendum, which is incorporated herein as Exhibit D of this DPA.
6.5 Transfers from Switzerland. The parties agree that transfers from Switzerland are made pursuant to the EU SCCs with the following modifications:
6.5.1 The terms “General Data Protection Regulation” or “Regulation (EU) 2016/679” as utilized in the EU SCCs shall be interpreted to include the Federal Act on Data Protection of 19 June 1992 (the “FADP,” and as revised as of 25 September 2020, the “Revised FADP”) with respect to data transfers subject to the FADP.
6.5.2 The terms of the EU SCCs shall be interpreted to protect the data of legal entities until the effective date of the Revised FADP.
6.5.3 Clause 13 of the EU SCCs is modified to provide that the Federal Data Protection and Information Commissioner (“FDPIC”) of Switzerland shall have authority over data transfers governed by the FADP and the appropriate EU supervisory authority shall have authority over data transfers governed by the GDPR. Subject to the foregoing, all other requirements of Section 13 shall be observed.
6.5.4 The term “EU Member State” as utilized in the EU SCCs shall not be interpreted in such a way as to exclude Data Subjects in Switzerland from exercising their rights in their place of habitual residence in accordance with Clause 18(c) of the EU SCCs.
6.6 Supplementary Measures. In respect of any ex-EEA Transfer or ex-UK Transfer, the following supplementary measures shall apply:
6.6.1 As of the date of this DPA, the Data Importer has not received any formal legal requests from any government intelligence or security service/agencies in the country to which the Personal Data is being exported, for access to (or for copies of) Customer’s Personal Data (“Government Agency Requests”)
6.6.2 If, after the date of this DPA, the Data Importer receives any Government Agency Requests, Mashgin shall attempt to redirect the law enforcement or government agency to request that data directly from the Customer. As part of this effort, Mashgin may provide Customer’s basic contact information to the government agency. If compelled to disclose Customer’s Personal Data to a law enforcement or government agency, Mashgin shall give Customer reasonable notice of the demand and cooperate to allow Customer to seek a protective order or other appropriate remedy unless Mashgin is legally prohibited from doing so. Mashgin shall not voluntarily disclose Personal Data to any law enforcement or government agency. Data Exporter and Data Importer shall (as soon as reasonably practicable) discuss and determine whether all or any transfers of Personal Data pursuant to this DPA should be suspended in the light of the such Government Agency Requests; and
6.6.3 The Data Exporter and Data Importer will meet regularly to consider whether:
(i) the protection afforded by the laws of the country of the Data Importer to data subjects whose Personal Data is being transferred is sufficient to provide broadly equivalent protection to that afforded in the EEA or the UK, whichever the case may be;
(ii) additional measures are reasonably necessary to enable the transfer to be compliant with the Data Protection Laws; and
(iii) it is still appropriate for Personal Data to be transferred to the relevant Data Importer, taking into account all relevant information available to the parties, together with guidance provided by the supervisory authorities.
6.6.4 If Data Protection Laws require the Data Exporter to execute the Standard Contractual Clauses applicable to a particular transfer of Personal Data to a Data Importer as a separate agreement, the Data Importer shall, on request of the Data Exporter, promptly execute such Standard Contractual Clauses incorporating such amendments as may reasonably be required by the Data Exporter to reflect the applicable appendices and annexes, the details of the transfer and the requirements of the relevant Data Protection Laws.
6.6.5 If either (i) any of the means of legitimizing transfers of Personal Data outside of the EEA or UK set forth in this DPA cease to be valid or (ii) any supervisory authority requires transfers of Personal Data pursuant to those means to be suspended, then Data Importer may by notice to the Data Exporter, with effect from the date set out in such notice, amend or put in place alternative arrangements in respect of such transfers, as required by Data Protection Laws.
7. Rights of Data Subjects
7.1 Mashgin shall, to the extent permitted by law, notify Customer upon receipt of a request by a Data Subject to exercise the Data Subject’s right of: access, rectification, erasure, data portability, restriction or cessation of processing, withdrawal of consent to processing, and/or objection to being subject to processing that constitutes automated decision-making (such requests individually and collectively “Data Subject Request(s)”). If Mashgin receives a Data Subject Request in relation to Customer’s data, Mashgin will advise the Data Subject to submit their request to Customer and Customer will be responsible for responding to such request, including, where necessary, by using the functionality of the Services. Customer is solely responsible for ensuring that Data Subject Requests for erasure, restriction or cessation of processing, or withdrawal of consent to processing of any Personal Data are communicated to Mashgin, and, if applicable, for ensuring that a record of consent to processing is maintained with respect to each Data Subject.
7.2 Mashgin shall, at the request of the Customer, and taking into account the nature of the processing applicable to any Data Subject Request, apply appropriate technical and organizational measures to assist Customer in complying with Customer’s obligation to respond to such Data Subject Request and/or in demonstrating such compliance, where possible, provided that (i) Customer is itself unable to respond without Mashgin’s assistance and (ii) Mashgin is able to do so in accordance with all applicable laws, rules, and regulations. Customer shall be responsible to the extent legally permitted for any costs and expenses arising from any such assistance by Mashgin.
8. Actions and Access Requests; Audits
8.1 Mashgin shall, taking into account the nature of the processing and the information available to Mashgin, provide Customer with reasonable cooperation and assistance where necessary for Customer to comply with its obligations under the GDPR to conduct a data protection impact assessment and/or to demonstrate such compliance, provided that Customer does not otherwise have access to the relevant information. Customer shall be responsible to the extent legally permitted for any costs and expenses arising from any such assistance by Mashgin.
8.2 Mashgin shall, taking into account the nature of the processing and the information available to Mashgin, provide Customer with reasonable cooperation and assistance with respect to Customer’s cooperation and/or prior consultation with any Supervisory Authority, where necessary and where required by the GDPR. Customer shall be responsible to the extent legally permitted for any costs and expenses arising from any such assistance by Mashgin.
8.3 Mashgin shall maintain records sufficient to demonstrate its compliance with its obligations under this DPA, and retain such records for a period of three (3) years after the termination of the Agreement. Customer shall, with reasonable notice to Mashgin, have the right to review, audit and copy such records at Mashgin’s offices during regular business hours.
8.4 Upon Customer’s written request at reasonable intervals, and subject to reasonable confidentiality controls, Mashgin shall, either (i) make available for Customer’s review copies of certifications or reports demonstrating Mashgin’s compliance with prevailing data security standards applicable to the processing of Customer’s Personal Data, or (ii) if the provision of reports or certifications pursuant to (i) is not reasonably sufficient under Data Protection Laws, allow Customer’s independent third party representative to conduct an audit or inspection of Mashgin’s data security infrastructure and procedures that is sufficient to demonstrate Mashgin’s compliance with its obligations under Data Protection Laws, provided that (a) Customer provides reasonable prior written notice of any such request for an audit and such inspection shall not be unreasonably disruptive to Mashgin’s business; (b) such audit shall only be performed during business hours and occur no more than once per calendar year; and (c) such audit shall be restricted to data relevant to Customer. Customer shall be responsible for the costs of any such audits or inspections, including without limitation a reimbursement to Mashgin for any time expended for on-site audits. If Customer and Mashgin have entered into Standard Contractual Clauses as described in Section 6 (Transfers of Personal Data), the parties agree that the audits described in Clause 8.9 of the EU SCCs shall be carried out in accordance with this Section 8.4.
8.5 Mashgin shall immediately notify Customer if an instruction, in Mashgin’s opinion, infringes the Data Protection Laws or Supervisory Authority.
8.6 In the event of a Personal Data Breach, Mashgin shall, without undue delay, inform Customer of the Personal Data Breach and take such steps as Mashgin in its sole discretion deems necessary and reasonable to remediate such violation (to the extent that remediation is within Mashgin’s reasonable control).
8.7 In the event of a Personal Data Breach, Mashgin shall, taking into account the nature of the processing and the information available to Mashgin, provide Customer with reasonable cooperation and assistance necessary for Customer to comply with its obligations under the GDPR with respect to notifying (i) the relevant Supervisory Authority and (ii) Data Subjects affected by such Personal Data Breach without undue delay.
8.8 The obligations described in Sections 8.6 and 8.7 shall not apply in the event that a Personal Data Breach results from the actions or omissions of Customer. Mashgin’s obligation to report or respond to a Personal Data Breach under Sections 8.6 and 8.7 will not be construed as an acknowledgement by Mashgin of any fault or liability with respect to the Personal Data Breach.
9. Mashgin’s Role as a Controller.
The parties acknowledge and agree that with respect to Mashgin Account Data and Mashgin Usage Data, Mashgin is an independent controller, not a joint controller with Customer. Mashgin will process Mashgin Account Data and Mashgin Usage Data as a controller (i) to manage the relationship with Customer; (ii) to carry out Mashgin’s core business operations, such as accounting, audits, tax preparation and filing and compliance purposes; (iii) to monitor, investigate, prevent and detect fraud, security incidents and other misuse of the Services, and to prevent harm to Customer; (iv) for identity verification purposes; (v) to comply with legal or regulatory obligations applicable to the processing and retention of Personal Data to which Mashgin is subject; and (vi) as otherwise permitted under Data Protection Laws and in accordance with this DPA and the Agreement. Mashgin may also process Mashgin Usage Data as a controller to provide, optimize, and maintain the Services, to the extent permitted by Data Protection Laws. Any processing by Mashgin as a controller shall be in accordance with Mashgin’s privacy policy set forth at https://www.mashgin.com/privacy-policy
10. Conflict.
In the event of any conflict or inconsistency among the following documents, the order of precedence will be: (1) the applicable terms in the Standard Contractual Clauses; (2) the terms of this DPA; (3) the Agreement; and (4) Mashgin’s privacy policy. Any claims brought in connection with this DPA will be subject to the terms and conditions, including, but not limited to, the exclusions and limitations set forth in the Agreement.
Exhibit A
Details of Processing
Nature and Purpose of Processing: Mashgin will process Customer’s Personal Data as necessary to provide the Services under the Agreement, for the purposes specified in the Agreement and this DPA, and in accordance with Customer’s instructions as set forth in this DPA. The nature of processing includes, without limitation:
- Receiving data, including collection, accessing, retrieval, recording, and data entry
- Holding data, including storage, organization and structuring
- Using data, including analysis, consultation, testing, automated decision making and profiling
- Updating data, including correcting, adaptation, alteration, alignment and combination
- Protecting data, including restricting, encrypting, and security testing
- Sharing data, including disclosure, dissemination, allowing access or otherwise making available
- Returning data to the data exporter or data subject
- Erasing data, including destruction and deletion
Duration of Processing: Mashgin will process Customer’s Personal Data as long as required (i) to provide the Services to Customer under the Agreement; (ii) for Mashgin’s legitimate business needs; or (iii) by applicable law or regulation. Mashgin Account Data and Mashgin Usage Data will be processed and stored as set forth in Mashgin’s privacy policy.
Categories of Data Subjects: Customer end-users/customers AND/OR Customer employees
Categories of Personal Data: Mashgin processes Personal Data contained in Mashgin Account Data, Mashgin Usage Data, and any Personal Data provided by Customer (including any Personal Data Customer collects from its end users and processes through its use of the Services) or collected by Mashgin in order to provide the Services or as otherwise set forth in the Agreement or this DPA. Categories of Personal Data include those specified in Mashgin’s privacy policy.
Sensitive Data or Special Categories of Data: None
Exhibit B
The following includes the information required by Annex I and Annex III of the EU SCCs, and Table 1, Annex 1A, and Annex 1B of the UK Addendum.
1. The Parties
Data exporter(s): The Customer
- Contact details: As designated by Customer in the contact detail section of the Order Form accompanying the Agreement.
- Signature and date: By entering into the Agreement, Data Exporter is deemed to have signed these Standard Contractual Clauses incorporated herein, as of the Effective Date of the Agreement.
- Role (controller/processor): The Data Exporter’s role is set forth in Section 2 of this Addendum.
Data importer(s): Mashgin
Address:
849 East Charleston Road, Palo Alto, California 94303, United States
Contact person’s name, position and contact details:
Cody Dales, VP Compliance, email: cody@mashgin.com, tel: +1 (276) 312-9295
Signature and date: By entering into the Agreement, Data Importer is deemed to have signed these Standard Contractual Clauses incorporated herein, as of the Effective Date of the Agreement.
Role (controller/processor): The Data Importer’s role is set forth in Section 2 of this Addendum.
2. Description of the Transfer
Data Subjects
As described in Exhibit A of the DPA
Categories of Personal Data
As described in Exhibit A of the DPA
Special Category Personal Data (if applicable)
As described in Exhibit A of the DPA
Nature of the Processing
As described in Exhibit A of the DPA
Purposes of Processing
As described in Exhibit A of the DPA
Duration of Processing and Retention (or the criteria to determine such period)
As described in Exhibit A of the DPA
Frequency of the transfer
As necessary to provide perform all obligations and rights with respect to Personal Data as provided in the Agreement
Recipients of Personal Data Transferred to the Data Importer
Mashgin will maintain and provide a list of its Subprocessors upon request. Mashgin’s list of Subprocessors can be found in the following list “List of Authorized Sub-Processors.”
3. Competent Supervisory Authority
The supervisory authority shall be the supervisory authority of the Data Exporter, as determined in accordance with Clause 13 of the EU SCCs. The supervisory authority for the purposes of the UK Addendum shall be the UK Information Commissioner’s Officer.
4. List of Authorized Sub-Processors
Name of Authorized Sub-Processor
Address
Contact Person Name, position, contact information
Description of processing
Country in which subprocessing will take place
Amazon Web Services, Inc. “AWS”
410 Terry Avenue North, Seattle, WA 98109-5210, USA
Kyle Larrow
klarrow@amazon.com
508-944-3017
https://aws.amazon.com/contact-us/compliance-support/
Cloud hosting, storage, and computing services; database management; content delivery and other infrastructural services.
USA
HubSpot, Inc.
25 First Street, 2nd Floor, Cambridge, MA 02141, USA
privacy@hubspot.com
Customer relationship management, marketing automation, email marketing, analytics, and customer service data management.
USA
Google, LLC
1600 Amphitheatre Parkway, Mountain View, CA 94043, USA
data-access-requests@google.com
tel: 650.253.0000
Email hosting, document storage and collaboration (Google Suite); website analytics, interactions, and data reporting (Google Analytics).
USA
Slack Technologies, LLC
500 Howard Street, San Francisco, CA 94105, USA
privacy@slack.com
Business communication platform providing messaging, file sharing, and collaboration tools.
USA
Twilio, Inc.
375 Beale Street, Suite 300, San Francisco, CA 94105, USA
privacy@twilio.com
Cloud communications platform offering messaging, voice, video, and email services.
USA
Zoom Video Communications, Inc.
55 Almaden Boulevard, 6th Floor, San Jose, CA 95113, USA
privacy@zoom.us
Video conferencing, web conferencing, and webinar hosting services.
USA
Postmark (Wildbit, LLC)
225 Chestnut Street, Philadelphia, PA 19106, USA
privacy@activecampaign.com
Email delivery service for transactional emails, including sending, receiving, and tracking emails.
USA
FreedomPay, Inc.
10 N Independence Mall W, Philadelphia, PA 19106, USA
compliance@freedompay.com
Payment processing services including transaction processing, data encryption, and financial data management.
USA
Intuit, Inc.
2700 Coast Avenue, Mountain View, CA 94043, USA
security@intuit.com
Financial and accounting software services, including tax preparation, payroll processing, and financial reporting.
USA
Zendesk, Inc.
989 Market Street, San Francisco, CA 94103, USA
privacy@zendesk.com
Customer service software and ticketing system providing support ticket tracking, customer support communications, and analytics.
USA
Service Now, Inc.
2225 Lowsome Lane, Santa Clara, CA 95054, USA
privacy@servicenow.com
Customer service software and ticketing system providing support ticket tracking, customer support communications, and analytics.
USA
Five9, Inc.
3001 Bishop Drive, Suite 350, San Ramon, CA 94583, USA
privacy@five9.com
Cloud communications platform offering messaging, voice, video, and email services.
USA
Click-Up (Mango Technologies, Inc.)
5800 Armada Drive, Suite 300, Carlsbad, CA 92008, USA
John Hussey
jhussey@clickup.com
(781) 439-1293
Project management tools offering task assignments, scheduling, document management, and collaboration features.
USA
Smartsheet, Inc.
10500 NE 8th Street, Suite 1300, Bellevue, WA 98004, USA
privacy@smartsheet.com
Work execution platform providing services for planning, tracking, automation, and reporting on work.
USA
Height
222 Broadway, New York City, New York, 10038, USA
team@height.app
Task management and collaboration software featuring task tracking, project management, and team collaboration tools.
USA
Okta, Inc.
100 First Street, Suite 600, San Francisco, CA 94105, USA
jake.mccarthy@okta.com
Identity management services including authentication, user management, and access control.
USA
Cloudflare, Inc.
101 Townsend St, San Francisco, CA 94107, USA
privacyquestions@cloudflare.com
Web infrastructure and security services such as DNS services, DDoS mitigation, and website performance optimization.
USA
Rippling (Rippling PEO 1, Inc.)
55 Second St, Suite 1500, San Francisco, CA 94105, USA
support@rippling.com
HR and IT management platform providing services such as payroll, benefits administration, employee onboarding, and device management.
USA
Plane (Pilot Platform Inc.)
548 Market St. #91283, San Francisco, CA 94104, USA
privacy@plane.com
Professional Employer Organization and employer of record for E.U.-based Mashgin staff. HR and payroll service.
USA
GitLab, Inc.
268 Bush Street, #350, San Francisco, CA 94104, USA
DPO@gitlab.com
Web-based DevOps lifecycle tool, offering code repository management.
USA
Testiny (Mategra GmbH)
Fasanstraße 25/14
8052 Graz
Austria
c.breitwieser@testiny.io
Software Quality Assurance “QA” testing automation software.
Austria
Windcave
1601 N 7th St Suite 420, Phoenix, AZ 85006, USA
support@windcave.com
Payment processing services including transaction processing, data encryption, and financial data management.
USA
Shift4 (Shift4 Payments LLC)
3501 Corporate Pkwy, Center Valley, PA 18034, USA
dpo@credorax.com
Payment processing services including transaction processing, data encryption, and financial data management.
USA
Exhibit C
Description of the Technical and Organizational Security Measures implemented by the Data Importer
The following includes the information required by Annex II of the EU SCCs and Annex II of the UK Addendum.
Technical and Organizational Security Measure
Details
Measures of pseudonymisation and encryption of personal data
At Rest: AES-256 / In Motion: ChaCha20 + TLS.
For services performed within the EU, Mashgin receives less data from its partner payment processors, such as XEPS, which does not include the Name on Card field (i.e. no personal data requires pseudonymisation). Mashgin does not apply pseudonymisation to Mashgin Cloud data, e.g. user’s name and email.
Measures for ensuring ongoing confidentiality, integrity, availability and resilience of processing systems and services
Mashgin maintains a Business Continuity and Disaster Recovery Policy that is reviewed annually by the Mashgin Compliance Council. Mashgin’s Compliance Council organizes an annual table-top exercise for disaster recovery.
Mashgin’s cloud services reside on Amazon Web Services. All internal data and APIs are contained within a private Virtual Private Cloud which is separate from the servers in our public VPC. All servers and kiosks are on an encrypted VPN over TLS that can only be accessed via a 2FA account with revocable privileges. Critical cloud servers are behind load balancers where capacity can be manually added on demand. Database and storage capacity also uses AWS so it can be scaled within and across availability zones on demand.
Mashgin’s database is automatically backed up multiple times daily through Amazon Web Services (“AWS”), and such backups are stored for one month thereafter. Mashgin performs a quarterly back-up restoration test.
Measures for ensuring the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident
All reporting data, user data, and item/menu data is stored on AWS cloud servers and backed up at least once per day. Such data is securely transferred through the Cloud over secure protocols to Amazon Web Services.
Physical security of service provider Amazon Web Services is the leading industry standard and documented publicly in the most recent SOC-II report for AWS. Mashgin currently defaults to AWS’s Boardman, Oregon data processing and storage facility.
Mashgin’s database is automatically backed up multiple times daily through Amazon Web Services (“AWS”), and such backups are stored for one month thereafter.
No sensitive information, including customer information, is permitted by Mashgin’s Information Security Policy to be stored locally. Rather, Mashgin’s Cloud architecture affords our clients’ data strong levels of encryption by means of its storage within industry-leading Amazon Web Services’ own data infrastructure and by means of TLS, SSH, and other relevant security protocols during transmission. All traffic is passed through our VPN which is ChaCha20 encrypted. Within this, all traffic is TLS encrypted.
Processes for regularly testing, assessing and evaluating the effectiveness of technical and organizational measures in order to ensure the security of the processing
Mashgin engages in once-yearly penetration testing by an accredited third party security firm.
Mashgin conducts an annual information security policy review, an annual risk management exercise, an annual business continuity and disaster recovery exercise, and a patch management program.
Mashgin utilizes the compliance automation and monitoring system Vanta to identify and act upon organizational weak spots to ensure appropriate implementation of required controls.
Measures for user identification and authorization
System administrators must sign-on and pass authentication via individual user accounts in order to gain access to administrative privileges to manage individual systems.
Access controls to Mashgin production systems are limited to the fewest number of employees as is strictly required, and all access hereto must be secured behind two-factor authentication at minimum. Where technologically feasible and pertinent, access must also be secured behind the self-managed Mashgin VPN.
All sensitive systems and applications must automatically enforce password strength requirements, history requirements, and reset requirements. For access to Google G-Suite accounts, strong password settings must be enabled across Company user accounts, and user account passwords must have a minimum length of ten characters, in compliance with the Strong Password Policy.
Measures for the protection of data during transmission
All traffic is passed through our VPN which is ChaCha20 encrypted. Within this, all traffic is TLS encrypted. Server data is encrypted via Amazon KMS.
Measures for the protection of data during storage
Data at rest is AES-256 encrypted.
Measures for ensuring physical security of locations at which personal data are processed
All reporting data, user data, and item/menu data is stored on AWS cloud servers and backed up at least once per day. Such data is securely transferred through the Cloud over secure protocols to Amazon Web Services.
Physical security of service provider Amazon Web Services is the leading industry standard and documented publicly in the most recent SOC-II report for AWS. Mashgin currently defaults to AWS’s Boardman, Oregon data processing and storage facility.
Measures for ensuring events logging
Mashgin operates an in-house logging system for its systems and infrastructure. Staff access to all data is logged. All access to customer data is controlled via an account system.
Changes and data updates are tracked via user and timestamp. Application logs are retained indefinitely. Our database is automatically backed up multiple times daily, with backups stored for one month. All AWS access is logged through AWS CloudTrail.
Measures for ensuring system configuration, including default configuration
N/A. Mashgin is a touchless checkout system and doesn't require a desktop workstation.
Measures for internal IT and IT security governance and management
Mashgin has established an internal council of department heads, the “Compliance Council”, to draft, review, and enforce various information security and operational policies and procedures.
The Compliance Council maintains a library of compliance policies it frequently reviews. Mashgin has several recurring processes to disseminate information from the leadership team, keep the team apprised of cyber security news and updates, and to monitor and ensure good corporate governance.
The Company is operated by a board of directors, conducts an annual ethical management survey, and utilizes advanced tools such as the Vanta automated compliance platform to monitor risk, security controls, and adherence to various security frameworks such as SOC 2.
Measures for certification/assurance of processes and products
Mashgin is SOC 2 Type 1 compliant.
Measures for ensuring data minimisation
Mashgin’s general policy is to process as little data as is required to render our services per contractual and legal obligations.
Measures for ensuring data quality
All client data is segregated logically. All data in our system is associated with a location. All locations belong to a unique client.
All customer data will be associated with a client ID but otherwise stored in the same cloud database.
Measures for ensuring limited data retention
All data in our system is associated with a location. All locations belong to a unique client. All customer data will be associated with a client ID but otherwise stored in the same cloud database.
Regarding physical access to Mashgin data, no personnel have access to the data storage facility maintained by Amazon Web Services. Regarding non-physical access, a fleshed-out policy and procedure exists within Mashgin’s InfoSec policy, and Mashgin seeks to provide only the minimum-required level of access and/or authority to personnel who may interact directly with sensitive data.
Mashgin maintains the most stringent level of access control as is feasible in the scope of Company staff and resources. This includes the requirement of usage of a virtual private network with company-provided secure credentials to access such data. Customer data is retained for the life of the customer contract, available for export upon contract termination, and then deleted after contract ends upon request.
Measures for ensuring accountability
Mashgin’s Compliance Council conducts twice-annual information security awareness training for all staff. Mashgin’s Compliance department routinely shares cyber security and compliance updates to the channel #infosec on the Company’s internal Slack instant messenger service.
Mashgin’s Compliance Council maintains a Compliance Library of various policies and procedures for information security and general operations, and requires all staff to sign and abide by the most current version of each policy.
Mashgin’s Compliance team also shares examples of phishing attacks and more to increase the cyber security awareness of all staff.
Measures for allowing data portability and ensuring erasure
Mashgin maintains an Asset Management Policy that governs the data portability, removable devices, and data erasure.
Mashgin also adheres to its Privacy Policy, publicly available on the web at https://www.mashgin.com/privacy-policy.
Technical and organizational measures of sub-processors
Sub-processors such as Amazon Web Services (AWS), Google LLC (for Google Suite and Google Analytics), Slack Technologies, LLC, and others, implement a range of robust technical and organizational measures to protect the personal data they process. These measures are designed to provide a high level of security and data protection, irrespective of the nature of the data being processed or the service being provided.
Common practices among these sub-processors include data encryption in transit and at rest, regular security assessments and penetration testing, and the deployment of firewalls and intrusion detection/prevention systems. These measures ensure the confidentiality, integrity, and availability of data, in line with GDPR’s Article 32 requirements.
To comply with GDPR, sub-processors enforce strict access control and data management policies. Measures such as role-based access control (RBAC), two-factor authentication, and stringent employee vetting processes are commonplace. This ensures that only authorized personnel have access to personal data, and only for necessary purposes as stipulated by the processing agreement.
Furthermore, sub-processors like Twilio Inc., Zoom Video Communications, Inc., and Intuit Inc. adopt data minimization principles, ensuring that only the necessary amount of data is processed and retained for the required duration. They also employ mechanisms for regular data backups, secure data deletion, and data recovery to safeguard against data loss or breaches.
Sub-processors maintain a proactive stance towards regulatory compliance and are subject to regular audits, both internal and external, to assess their adherence to GDPR and other privacy standards. Companies such as Zendesk, Inc., ClickUp, and Cloudflare, Inc. not only comply with GDPR but often align with other international standards like ISO/IEC 27001, SOC 2, and others, further testifying to their commitment to data security.
They engage in ongoing risk assessment and mitigation strategies, ensuring that their security postures evolve in response to new threats and changes in the regulatory landscape. Additionally, these sub-processors are transparent in their data processing activities, providing data subjects with rights such as access, rectification, erasure, and portability as mandated by the GDPR.
Exhibit D
UK Addendum
International Data Transfer Addendum to the EU Commission Standard Contractual Clauses
Part 1: Tables
Start Date
This UK Addendum shall have the same effective date as the DPA
The Parties
Exporter
Importer
Parties’ Details
Customer
Mashgin
Key Contact
See Exhibit B of this DPA
See Exhibit B of this DPA
Table 2: Selected SCCs, Modules and Selected Clauses
EU SCCs
The Version of the Approved EU SCCs which this UK Addendum is appended to as defined in the DPA and completed by Section 6.2 and 6.3 of the DPA.
Table 3: Appendix Information
“Appendix Information” means the information which must be provided for the selected modules as set out in the Appendix of the Approved EU SCCs (other than the Parties), and which for this UK Addendum is set out in:
Annex 1A: List of Parties
As per Table 1 above
Annex 2B: Description of Transfer
See Exhibit B of this DPA
Annex II: Technical and organizational measures including technical and organizational measures to ensure the security of the data:
See Exhibit C of this DPA
Annex III: List of Sub processors (Modules 2 and 3 only):
See Exhibit B of this DPA
Table 4: Ending this UK Addendum when the Approved UK Addendum Changes
Ending this UK Addendum when the Approved UK Addendum changes
☒ Importer
☐ Exporter
☐ Neither Party
Entering into this UK Addendum:
1. Each party agrees to be bound by the terms and conditions set out in this UK Addendum, in exchange for the other party also agreeing to be bound by this UK Addendum.
2. Although Annex 1A and Clause 7 of the Approved EU SCCs require signature by the Parties, for the purpose of making ex-UK Transfers, the Parties may enter into this UK Addendum in any way that makes them legally binding on the Parties and allows data subjects to enforce their rights as set out in this UK Addendum. Entering into this UK Addendum will have the same effect as signing the Approved EU SCCs and any part of the Approved EU SCCs.
Interpretation of this UK Addendum
3. Where this UK Addendum uses terms that are defined in the Approved EU SCCs those terms shall have the same meaning as in the Approved EU SCCs. In addition, the following terms have the following meanings:
UK Addendum
means this International Data Transfer Addendum incorporating the EU SCCs, attached to the DPA as Exhibit D.
EU SCCs
means the version(s) of the Approved EU SCCs which this UK Addendum is appended to, as set out in Table 2, including the Appendix Information.
Appendix Information
shall be as set out in Table 3.
Appropriate Safeguards
means the standard of protection over the personal data and of data subjects’ rights, which is required by UK Data Protection Laws when you are making an ex-UK Transfer relying on standard data protection clauses under Article 46(2)(d) UK GDPR.
Approved UK Addendum
means the template Addendum issued by the ICO and laid before Parliament in accordance with s119A of the Data Protection Act 2018 on 2 February 2022, as may be revised under Section 19 of the UK Addendum.
Approved EU SCCs
means the standard contractual clauses approved by the European Commission in Commission Decision 2021/914 dated 4 June 2021, for transfers of personal data to countries not otherwise recognized as offering an adequate level of protection for personal data by the European Commission (as amended and updated from time to time).
ICO
means the Information Commissioner of the United Kingdom.
ex-UK Transfer
shall have the same definition as set forth in the DPA.
UK
means the United Kingdom of Great Britain and Northern Ireland.
UK Data Protection Laws
means all laws relating to data protection, the processing of personal data, privacy and/or electronic communications in force from time to time in the UK, including the UK GDPR and the Data Protection Act 2018.
UK GDPR
shall have the definition set forth in the DPA.
4. The UK Addendum must always be interpreted in a manner that is consistent with UK Data Protection Laws and so that it fulfills the Parties’ obligation to provide the Appropriate Safeguards.
5. If the provisions included in the UK Addendum amend the Approved EU SCCs in any way which is not permitted under the Approved EU SCCs or the Approved UK Addendum, such amendment(s) will not be incorporated in the UK Addendum and the equivalent provision of the Approved EU SCCs will take their place.
6. If there is any inconsistency or conflict between UK Data Protection Laws and the UK Addendum, UK Data Protection Laws apply.
7. If the meaning of the UK Addendum is unclear or there is more than one meaning, the meaning which most closely aligns with UK Data Protection Laws applies.
8. Any references to legislation (or specific provisions of legislation) means that legislation (or specific provision) as it may change over time. This includes where that legislation (or specific provision) has been consolidated, re-enacted and/or replaced after the UK Addendum has been entered into.
Hierarchy
9. Although Clause 5 of the Approved EU SCCs sets out that the Approved EU SCCs prevail over all related agreements between the parties, the parties agree that, for ex-UK Transfers, the hierarchy in Section 10 below will prevail.
10. Where there is any inconsistency or conflict between the Approved UK Addendum and the EU SCCs (as applicable), the Approved UK Addendum overrides the EU SCCs, except where (and in so far as) the inconsistent or conflicting terms of the EU SCCs provides greater protection for data subjects, in which case those terms will override the Approved UK Addendum.
11. Where this UK Addendum incorporates EU SCCs which have been entered into to protect ex-EU Transfers subject to the GDPR, then the parties acknowledge that nothing in the UK Addendum impacts those EU SCCs.
Incorporation and Changes to the EU SCCs:
12. This UK Addendum incorporates the EU SCCs which are amended to the extent necessary so that:
a) together they operate for data transfers made by the data exporter to the data importer, to the extent that UK Data Protection Laws apply to the data exporter’s processing when making that data transfer, and they provide Appropriate Safeguards for those data transfers;
b) Sections 9 to 11 above override Clause 5 (Hierarchy) of the EU SCCs; and
13. the UK Addendum (including the EU SCCs incorporated into it) is (1) governed by the laws of England and Wales and (2) any dispute arising from it is resolved by the courts of England and Wales.
14. Unless the parties have agreed alternative amendments which meet the requirements of Section 12 of this UK Addendum, the provisions of Section 15 of this UK Addendum will apply.
15. No amendments to the Approved EU SCCs other than to meet the requirements of Section 12 of this UK Addendum may be made.
16. The following amendments to the EU SCCs (for the purpose of Section 12 of this UK Addendum) are made:
a) References to the “Clauses” means this UK Addendum, incorporating the EU SCCs;
b) In Clause 2, delete the words: “and, with respect to data transfers from controllers to processors and/or processors to processors, standard contractual clauses pursuant to Article 28(7) of Regulation (EU) 2016/679”,
c) Clause 6 (Description of the transfer(s)) is replaced with: “The details of the transfers(s) and in particular the categories of personal data that are transferred and the purpose(s) for which they are transferred) are those specified in Annex I.B where UK Data Protection Laws apply to the data exporter’s processing when making that transfer.”;
d) Clause 8.7(i) of Module 1 is replaced with: “it is to a country benefiting from adequacy regulations pursuant to Section 17A of the UK GDPR that covers the onward transfer”;
e) Clause 8.8(i) of Modules 2 and 3 is replaced with: “the onward transfer is to a country benefiting from adequacy regulations pursuant to Section 17A of the UK GDPR that covers the onward transfer;”
f) References to “Regulation (EU) 2016/679”, “Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation)” and “that Regulation” are all replaced by “UK Data Protection Laws”. References to specific Article(s) of “Regulation (EU) 2016/679” are replaced with the equivalent Article or Section of UK Data Protection Laws;
g) References to Regulation (EU) 2018/1725 are removed;
h) References to the “European Union”, “Union”, “EU”, “EU Member State”, “Member State” and “EU or Member State” are all replaced with the “UK”;
i) The reference to “Clause 12(c)(i)” at Clause 10(b)(i) of Module one, is replaced with “Clause 11(c)(i)”;
j) Clause 13(a) and Part C of Annex I are not used;
k) The “competent supervisory authority” and “supervisory authority” are both replaced with the “Information Commissioner”;
l) In Clause 16(e), subsection (i) is replaced with: “the Secretary of State makes regulations pursuant to Section 17A of the Data Protection Act 2018 that cover the transfer of personal data to which these clauses apply;”;
m) Clause 17 is replaced with: “These Clauses are governed by the laws of England and Wales;
n) Clause 18 is replaced with: “Any dispute arising from these Clauses shall be resolved by the courts of England and Wales. A data subject may also bring legal proceedings against the data exporter and/or data importer before the courts of any country in the UK. The parties agree to submit themselves to the jurisdiction of such courts.”; and
o) The footnotes to the Approved EU SCCs do not form part of the UK Addendum, except for footnotes 8, 9, 10 and 11.
Amendments to the UK Addendum
17. The parties may agree to change Clauses 17 and/or 18 of the EU SCCs to refer to the laws and/or courts of Scotland and Northern Ireland.
18. If the parties wish to change the format of the information included in Part 1: Tables of the Approved UK Addendum, they may do so by agreeing to the change in writing, provided that the change does not reduce the Appropriate Safeguards.
19. From time to time, the ICO may issue a revised Approved UK Addendum which:
a) makes reasonable and proportionate changes to the Approved UK Addendum, including correcting errors in the Approved UK Addendum; and/or
b) reflects changes to UK Data Protection Laws;
The revised Approved UK Addendum will specify the start date from which the changes to the Approved UK Addendum are effective and whether the parties need to review this UK Addendum including the Appendix Information. This UK Addendum is automatically amended as set out in the revised Approved UK Addendum from the start date specified.
20. If the ICO issues a revised Approved UK Addendum under Section 18 of this UK Addendum, if a party will as a direct result of the changes in the Approved UK Addendum have a substantial, disproportionate and demonstrable increase in:
c) its direct costs of performing its obligations under the UK Addendum; and/or
d) its risk under the UK Addendum,
and in either case it has first taken reasonable steps to reduce those costs or risks so that it is not substantial and disproportionate, then that party may end this UK Addendum at the end of a reasonable notice period, by providing written notice for that period to the other party before the start date of the revised Approved UK Addendum.
21. The parties do not need the consent of any third party to make changes to this UK Addendum, but any changes must be made in accordance with its terms
Exhibit E
United States Privacy Law Exhibit
This United States Privacy Law Exhibit (“Exhibit”) supplements the DPA and includes additional information required by the CCPA, the VCDPA, the CPA, the CTDPA, the UCPA, and the MHMDA in each case, as updated, amended or replaced from time to time. Any terms not defined in this Exhibit shall have the meanings set forth in the DPA and/or the Agreement.
A. CALIFORNIA
1. Definitions
- For purposes of this Section A, the terms “Business,” “Business Purpose,” “Commercial Purpose,” “Consumer,” “Personal Information,” “Processing,” “Sell,” “Service Provider,” “Share,” and “Verifiable Consumer Request” shall have the meanings set forth in the CCPA.
- All references to “Personal Data,” “Controller,” “Processor,” and “Data Subject” in the DPA shall be deemed to be references to “Personal Information,” “Business,” “Service Provider,” and “Consumer,” respectively, as defined in the CCPA.
2. Obligations
- Except with respect to Mashgin Account Data and Mashgin Usage Data (as defined in the DPA), the parties acknowledge and agree that Mashgin is a Service Provider for the purposes of the CCPA (to the extent it applies) and Mashgin is receiving Personal Information from Customer in order to provide the Services pursuant to the Agreement, which constitutes a Business Purpose.
- Customer shall disclose Personal Information to Mashgin only for the limited and specified purposes described in Exhibit A to this DPA.
- Mashgin shall not Sell or Share Personal Information provided by Customer under the Agreement.
- Mashgin shall not retain, use, or disclose Personal Information provided by Customer pursuant to the Agreement for any purpose, including a Commercial Purpose, other than as necessary for the specific purpose of performing the Services for Customer pursuant to the Agreement, or as otherwise set forth in the Agreement or as permitted by the CCPA.
- Mashgin shall not retain, use, or disclose Personal Information provided by Customer pursuant to the Agreement outside of the direct business relationship between Mashgin and Customer, except where and to the extent permitted by the CCPA.
- Mashgin shall notify Customer if it makes a determination that it can no longer meet its obligations under the CCPA.
- Mashgin will not combine Personal Information received from, or on behalf of, Customer with Personal Information that it receives from, or on behalf of, another party, or that it collects from its own interaction with the Consumer.
- Mashgin shall comply with all obligations applicable to Service Providers under the CCPA, including by providing Personal Information provided by Customer under the Agreement the level of privacy protection required by CCPA.
- Mashgin shall only engage a new subprocessor to assist Mashgin in providing the Services to Customer under the Agreement in accordance with Section 4.1 of the DPA, including, without limitation, by: (i) notifying Customer of such engagement via the notification mechanism described in Section 4.1 of the DPA at least ten (10) days before enabling a new Subprocessor; and (ii) entering into a written contract with the subprocessor requiring subprocessor to observe all of the applicable requirements set forth in the CCPA.
3. Consumer Rights
- Mashgin shall assist Customer in responding to Verifiable Consumer Requests to exercise the Consumer’s rights under the CCPA as set forth in Section 7 of the DPA.
4. Audit and Remediation Rights
- To the extent required by CCPA, Mashgin shall allow Customer to conduct inspections or audits in accordance with Sections 8.3 and 8.4 of the DPA.
- If Customer determines that Mashgin is Processing Personal Information in an unauthorized manner, Customer may, taking into account the nature of the Mashgin’s Processing and the nature of the Personal Information Processed by Mashgin on behalf of Customer, take commercially reasonable and appropriate steps to stop and remediate such unauthorized Processing.
B. VIRGINIA
1. Definitions
- For purposes of this Section B, the terms “Consumer,” “Controller,” “Personal Data,” “Processing,” and “Processor” shall have the meanings set forth in the VCDPA.
- All references to “Data Subject” in this DPA shall be deemed to be references to “Consumer” as defined in the VCDPA.
2. Obligations
- Except with respect to Mashgin Account Data and Mashgin Usage Data (as defined in the DPA), the parties acknowledge and agree that Customer is a Controller and Mashgin is a Processor for the purposes of the VCDPA (to extent it applies).
- The nature, purpose, and duration of Processing, as well as the types of Personal Data and categories of Consumers are described in Exhibit A to this DPA.
- Mashgin shall adhere to Customer’s instructions with respect to the Processing of Customer Personal Data and shall assist Customer in meeting its obligations under the VCDPA by:
- Assisting Customer in responding to Consumer rights requests under the VCDPA as set forth in Section 7 of the DPA;
- Complying with Section 5 (“Security of Personal Data”) of the DPA with respect to Personal Data provided by Customer;
- In the event of a Personal Data Breach, providing information sufficient to enable Customer to meet its obligations pursuant to Virginia’s breach notification laws (Va. Code § 18.2-186.6); and
- Providing information sufficient to enable Customer to conduct and document data protection assessments to the extent required by VCDPA.
- Mashgin shall maintain the confidentiality of Personal Data provided by Customer and require that each person Processing such Personal Data be subject to a duty of confidentiality with respect to such Processing.
- Upon Customer’s written request, Mashgin shall delete or return all Personal Data provided by Customer in accordance with Section 2.4 of the DPA, unless retention of such Personal Data is required or authorized by law or the DPA and/or Agreement.
- In the event that Mashgin engages a new subprocessor to assist Mashgin in providing the Services to Customer under the Agreement, Mashgin shall enter into a written contract with the subprocessor requiring subprocessor to observe all of the applicable requirements of a Processor set forth in the VCDPA.
3. Audit Rights
- Upon Customer’s written request at reasonable intervals, Mashgin shall, as set forth in Sections 8.3-8.4 of the DPA, (i) make available to Customer all information in its possession that is reasonably necessary to demonstrate Mashgin’s compliance with its obligations under the VCDPA and (ii) allow and cooperate with reasonable inspections or audits as required under the VCDPA.
C. COLORADO
1. Definitions
- For purposes of this Section C, the terms “Consumer,” “Controller,” “Personal Data,” “Processing,” and “Processor” shall have the meanings set forth in the CPA.
- All references to “Data Subject” in the DPA shall be deemed to be references to “Consumer” as defined in the CPA.
2. Obligations
- Except with respect to Mashgin Account Data and Mashgin Usage Data (as defined in the DPA), the parties acknowledge and agree that Customer is a Controller and Mashgin is a Processor for the purposes of the CPA (to extent it applies).
- The nature, purpose, and duration of Processing, as well as the types of Personal Data and categories of Consumers are described in Exhibit A to this DPA.
- Mashgin shall require that each person Processing such Personal Data be subject to a duty of confidentiality with respect to such Processing.
- Mashgin shall only engage a new subcontractor to assist Mashgin in providing the Services to Customer under the Agreement in accordance with Section 4.1 of the DPA, including, without limitation, by: (i) notifying Customer of such engagement via the notification mechanism described in Section 4.1 of the DPA and providing Customer with an opportunity to object and (ii) entering into a written contract with the subcontractor requiring subcontractor to observe all of the applicable requirements set forth in the CPA.
- Mashgin shall be responsible for taking the appropriate technical and organizational measures as described in Exhibit C. Customer shall be responsible for implementing appropriate technical and organizational measures to ensure a level of security appropriate to the risk.
- Upon Customer’s written request, Mashgin shall delete or return all Personal Data provided by Customer in accordance with Section 2.4 of the DPA, unless retention of such Personal Data is required or authorized by law or the DPA and/or Agreement.
3. Audit Rights
- Upon Customer’s written request at reasonable intervals, Mashgin shall, as set forth in Sections 8.3-8.4 of the DPA, (i) make available to Customer all information in its possession that is reasonably necessary to demonstrate Mashgin’s compliance with its obligations under the CPA and (ii) allow and cooperate with reasonable inspections or audits as required or permitted under the CPA.
D. CONNECTICUT
1. Definitions
- For purposes of this Section D, the terms “Consumer,” “Controller,” “Personal Data,” “Processing,” and “Processor” shall have the meanings set forth in the CTDPA.
- All references to “Data Subject” in the DPA shall be deemed to be references to “Consumer” as defined in the CTDPA.
2. Obligations
- Except with respect to Mashgin Account Data and Mashgin Usage Data (as defined in the DPA), the parties acknowledge and agree that Customer is a Controller and Mashgin is a Processor for the purposes of the CTDPA (to extent it applies).
- The nature, purpose, and duration of Processing, as well as the types of Personal Data and categories of Consumers are described in Exhibit A to this DPA.
- Mashgin shall require that each person Processing such Personal Data be subject to a duty of confidentiality with respect to such Processing.
- Mashgin shall only engage a new subcontractor to assist Mashgin in providing the Services to Customer under the Agreement in accordance with Section 4.1 of the DPA, including, without limitation, by: (i) notifying Customer of such engagement via the notification mechanism described in Section 4.1 of the DPA and providing Customer with an opportunity to object and (ii) entering into a written contract with the subcontractor requiring subcontractor to observe all of the applicable requirements set forth in the CTDPA.
- Upon Customer’s written request, Mashgin shall delete or return all Personal Data provided by Customer in accordance with Section 2.4 of the DPA, unless retention of such Personal Data is required or authorized by law or the DPA and/or Agreement.
3. Audit Rights
- Upon Customer’s written request at reasonable intervals, Mashgin shall, as set forth in Sections 8.3-8.4 of the DPA, (i) make available to Customer all information in its possession that is reasonably necessary to demonstrate Mashgin’s compliance with its obligations under the CTDPA and (ii) allow and cooperate with reasonable inspections or audits as required under the CTDPA.
E. UTAH
1. Definitions
- For purposes of this Section E, the terms “Consumer,” “Controller,” “Personal Data,” “Processing,” and “Processor” shall have the meanings set forth in the UCPA.
- All references to “Data Subject” in the DPA shall be deemed to be references to “Consumer” as defined in the UCPA.
2. Obligations
- Except with respect to Mashgin Account Data and Mashgin Usage Data (as defined in the DPA), the parties acknowledge and agree that Customer is a Controller and Mashgin is a Processor for the purposes of the UCPA (to extent it applies).
- The instructions with respect to the Processing of Customer Personal Data and the parties’ rights and obligations are set forth in this DPA and the Agreement.
- The nature, purpose, and duration of Processing, as well as the types of Personal Data and categories of Consumers are described in Exhibit A to this DPA.
- Mashgin shall require that each person Processing such Personal Data be subject to a duty of confidentiality with respect to such Processing.
- Mashgin shall only engage a new subcontractor to assist Mashgin in providing the Services to Customer under the Agreement in accordance with Section 4.1 of the DPA, including, without limitation, by entering into a written contract with the subcontractor requiring subcontractor to observe all of the applicable requirements set forth in the UCPA.
F. WASHINGTON
1. Definitions
- For purposes of this Section F, the terms “Consumer Health Data,” “Processor,” “Regulated Entity,” “Small Business,” and “Process” or “Processing” shall have the meanings set forth in the MHMDA.
- All references to “Data Subject” in the DPA shall be deemed to be references to “Consumer” as defined in the MHMDA.
2. Obligations
- Except with respect to Mashgin Account Data and Mashgin Usage Data (as defined in the DPA), the parties acknowledge and agree that Mashgin is a Processor for the purposes of the MHMDA (to the extent it applies).
- The Customer’s instructions with respect to the Mashgin’s Processing of Consumer Health Data and each party’s respective rights and obligations are set forth in this DPA and the Agreement.
- The nature, purpose, and duration of Processing, as well as the types of Consumer Health Data and categories of Consumers are described in Exhibit A to this DPA.
- Mashgin shall be responsible for taking the appropriate technical and organizational measures as described in Exhibit C. Customer shall be responsible for implementing appropriate technical and organizational measures to ensure a level of security appropriate to the risk.
- Mashgin acknowledges that if it fails to adhere to Customer’s instructions or processes Consumer Health Data outside of the scope of the Agreement or this DPA, Mashgin may be subject to all the obligations as a Regulated Entity or a Small Business, as applicable, pursuant to the MHMDA.
<!DOCTYPE html><!-- Last Published: Fri Feb 13 2026 10:47:50 GMT+0000 (Coordinated Universal Time) --><html data-wf-domain="www.mashgin.com" data-wf-page="69123b06dd2854552c429536" data-wf-site="603557fca6b5097977fbac59"><head><meta charset="utf-8"/><title>Data Processing Addendum</title><meta content="Read the Mashgin Data Processing Addendum" name="description"/><meta content="Data Processing Addendum" property="og:title"/><meta content="Read the Mashgin Data Processing Addendum" property="og:description"/><meta content="https://cdn.prod.website-files.com/603557fca6b5097977fbac59/6446ef659590ff5f13be2119_Homepage-Preview-V2.jpg" property="og:image"/><meta content="Data Processing Addendum" property="twitter:title"/><meta content="Read the Mashgin Data Processing Addendum" property="twitter:description"/><meta content="https://cdn.prod.website-files.com/603557fca6b5097977fbac59/6446ef659590ff5f13be2119_Homepage-Preview-V2.jpg" property="twitter:image"/><meta property="og:type" content="website"/><meta content="summary_large_image" name="twitter:card"/><meta content="width=device-width, initial-scale=1" name="viewport"/><meta content="3GXEYIQWejVVjmRIt820t6Zp8dHwXR4p5kLX3CxXoxE" name="google-site-verification"/><link href="https://cdn.prod.website-files.com/603557fca6b5097977fbac59/css/mashgin-6a5499c78811d71efcf3f7f31c8f03d.webflow.shared.df7e3e90e.min.css" rel="stylesheet" type="text/css" integrity="sha384-334+kOrM7sGzk45Nft7voUur7r+zqfVNLDsHw2DOPOVTubYHcAqLnpQlf0gv8Skn" crossorigin="anonymous"/><link href="https://fonts.googleapis.com" rel="preconnect"/><link href="https://fonts.gstatic.com" rel="preconnect" crossorigin="anonymous"/><script src="https://ajax.googleapis.com/ajax/libs/webfont/1.6.26/webfont.js" type="text/javascript"></script><script type="text/javascript">WebFont.load({ google: { families: ["Lato:100,100italic,300,300italic,400,400italic,700,700italic,900,900italic","Montserrat:100,100italic,200,200italic,300,300italic,400,400italic,500,500italic,600,600italic,700,700italic,800,800italic,900,900italic","Host Grotesk:300,400,500,600,700","Manrope:300,400,500,600,700","Outfit:300,400,500,600,700","Red Hat Display:300,400,500,600,700","Sansation:300,400,500,600,700","Sansation:300,400,500,600,700"] }});</script><script type="text/javascript">!function(o,c){var n=c.documentElement,t=" w-mod-";n.className+=t+"js",("ontouchstart"in o||o.DocumentTouch&&c instanceof DocumentTouch)&&(n.className+=t+"touch")}(window,document);</script><link href="https://cdn.prod.website-files.com/603557fca6b5097977fbac59/603557fca6b50922b2fbaca6_mashgin-favicon.png" rel="shortcut icon" type="image/x-icon"/><link href="https://cdn.prod.website-files.com/603557fca6b5097977fbac59/603557fca6b5099e40fbaca7_mashgin-webclip.jpg" rel="apple-touch-icon"/><link href="https://www.mashgin.com/data-processing-addendum" rel="canonical"/><script async="" src="https://www.googletagmanager.com/gtag/js?id=UA-151562406-1"></script><script type="text/javascript">window.dataLayer = window.dataLayer || [];function gtag(){dataLayer.push(arguments);}gtag('js', new Date());gtag('config', 'UA-151562406-1', {'anonymize_ip': false});</script><!-- Osano Cookie Management -->
<script src="https://cmp.osano.com/16CNMMU3jWNw32mW9/173d102c-2db4-411b-8e6e-3a292ee88909/osano.js"></script>
<!-- Google Tag Manager -->
<script>(function(w,d,s,l,i){w[l]=w[l]||[];w[l].push({'gtm.start':
new Date().getTime(),event:'gtm.js'});var f=d.getElementsByTagName(s)[0],
j=d.createElement(s),dl=l!='dataLayer'?'&l='+l:'';j.async=true;j.src=
'https://www.googletagmanager.com/gtm.js?id='+i+dl;f.parentNode.insertBefore(j,f);
})(window,document,'script','dataLayer','GTM-W2V7C3K');</script>
<!-- End Google Tag Manager -->
<script> (function(options) { var s = document.createElement("script"); s.async = true; s.src = "https://cdn.metadata.io/site-script.js"; s.onload = function() { window.Metadata.siteScript.init(options); }; document.head.appendChild(s); })({ accountId: 4220 }); </script>
<style>
body {
-moz-osx-font-smoothing: grayscale;
-webkit-font-smoothing: antialiased;
}
</style></head><body class="c-body"><div class="w-embed"><style>
body {
font-size: 1vw;
}
/* 9px body font size below 767px screens */
@media only screen and (max-width: 767px) {
body {font-size: 9px;}
}
/* Link color inherits from parent font color */
a {
color: inherit;
}
.w-dropdown-toggle {
color: inherit;
}
input, textarea, select {
-webkit-appearance: none;
-moz-appearance: none;
appearance: none; border-radius: 0;
background-image: none;
h1, h2, h3, h4, h5, h6 {
text-wrap: balance;
}
</style>
<!-- Buttons -->
<style>
/* ===== Staggered letter-by-letter hover swap for .c-button =====
- Text + arrow color always inherit from .c-button
- Control colors only via:
.c-button { color: ...; background: ... }
.c-button:hover { color: ...; background: ... }
- Transparent variant (.cc-transparent) keeps text white on hover
*/
/* Base button */
.c-button {
--speed: 280ms;
--easing: cubic-bezier(.2,.8,.2,1);
--stagger: 28ms;
display: inline-flex;
align-items: center;
gap: 0.5rem;
text-decoration: none;
/* Set your defaults here */
color: #000000; /* base text/arrow color */
background: #e7f61c; /* base background (example) */
}
/* Default hover (text/arrow color can change here if you want) */
.c-button:hover,
.c-button:focus-visible {
color: #000000; /* hover text/arrow color */
outline: none;
}
/* Label container */
.c-button_text {
display: inline-flex;
overflow: hidden;
white-space: nowrap;
}
/* Per-character wrapper (created by JS) */
.c-button_char {
display: inline-block;
position: relative;
overflow: hidden;
}
/* Two stacked copies of each character */
.c-button_char > span {
display: block;
will-change: transform;
transition-property: transform, color;
transition-duration: var(--speed);
transition-timing-function: var(--easing);
transition-delay: calc(var(--i, 0) * var(--stagger)); /* per-letter stagger */
transform: translate3d(0,0,0);
color: inherit; /* inherit from .c-button */
}
/* Top copy visible initially */
.c-button_char > span:first-child {
transform: translateY(0%);
}
/* Bottom copy starts hidden below */
.c-button_char > span:last-child {
position: absolute;
inset: 0 auto auto 0; /* align top/left; width follows content */
transform: translateY(100%);
}
/* Hover/focus: swap the two copies */
.c-button:hover .c-button_char > span:first-child,
.c-button:focus-visible .c-button_char > span:first-child {
transform: translateY(-100%);
}
.c-button:hover .c-button_char > span:last-child,
.c-button:focus-visible .c-button_char > span:last-child {
transform: translateY(0%);
}
/* Arrow micro-interaction (optional) */
.c-button_arrow {
transition: transform var(--speed) var(--easing);
}
.c-button:hover .c-button_arrow,
.c-button:focus-visible .c-button_arrow {
transform: translateX(2px);
}
/* Transparent variant: keep text white on hover */
.c-button.cc-transparent {
background: transparent;
color: #ffffff; /* base */
}
.c-button.cc-transparent:hover,
.c-button.cc-transparent:focus-visible {
color: #ffffff; /* stay white on hover */
}
/* Reduced motion */
@media (prefers-reduced-motion: reduce) {
.c-button_char > span,
.c-button_arrow {
transition: none;
}
}
</style></div><div fs-scrolldisable-element="smart-nav" data-animation="default" data-collapse="medium" data-duration="0" data-easing="ease" data-easing2="ease" role="banner" class="c-nav-v2 w-nav"><div class="c-container cc-nav"><div id="w-node-e677754d-587f-275b-2766-46bbb3c92df0-be3058cc" class="c-nav_menu-container"><a href="/" aria-label="Mashgin" class="c-nav_logo-wrap w-inline-block"><img id="black-logo" loading="eager" alt="" src="https://cdn.prod.website-files.com/603557fca6b5097977fbac59/68ba93408a431b3050ec1e87_Logo.png" class="c-nav_logo"/></a><nav role="navigation" id="w-node-e677754d-587f-275b-2766-46bbb3c92df3-be3058cc" class="c-nav_menu-wrap w-nav-menu"><div id="w-node-e677754d-587f-275b-2766-46bbb3c92df4-be3058cc" class="c-nav_menu"><div class="c-nav_menu-content"><div data-delay="0" data-hover="true" class="c-nav_dropdown w-dropdown"><div class="c-nav_dropdown-toggle w-dropdown-toggle"><div class="c-nav_text">Solution</div><div class="c-icon cc-xs w-embed"><svg width="100%" height="100%" viewBox="0 0 13 8" fill="none" xmlns="http://www.w3.org/2000/svg">
<path d="M1.104 1.5L6.104 6.5L11.104 1.5" stroke="currentcolor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"/>
</svg></div></div><nav class="c-nav_dropdown-menu_wrap cc-solutions w-dropdown-list"><div id="nav-scrollable" class="c-nav_dropdown-menu"><div class="c-wrap cc-z_1 cc-width_100 cc-gap_0"><a href="/solution/overview" class="c-nav_dropdown-menu_item w-inline-block"><div class="c-nav_text">Platform Overview</div></a><a href="/solution/integrations" class="c-nav_dropdown-menu_item w-inline-block"><div class="c-nav_text">Integrations</div></a><a href="/solution/deployment" class="c-nav_dropdown-menu_item w-inline-block"><div class="c-nav_text">Deployment</div></a><a href="/solution/mashgin-photos" class="c-nav_dropdown-menu_item w-inline-block"><div class="c-nav_text">Photo Gallery</div></a><a href="/solution/video-gallery" class="c-nav_dropdown-menu_item w-inline-block"><div class="c-nav_text">Video Gallery</div></a></div></div></nav></div><div data-delay="0" data-hover="true" class="c-nav_dropdown w-dropdown"><div class="c-nav_dropdown-toggle w-dropdown-toggle"><div class="c-nav_text">Industries</div><div class="c-icon cc-xs w-embed"><svg width="100%" height="100%" viewBox="0 0 13 8" fill="none" xmlns="http://www.w3.org/2000/svg">
<path d="M1.104 1.5L6.104 6.5L11.104 1.5" stroke="currentcolor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"/>
</svg></div></div><nav class="c-nav_dropdown-menu_wrap w-dropdown-list"><div id="nav-scrollable" class="c-nav_dropdown-menu"><div class="c-wrap cc-z_1 cc-width_100 cc-gap_0"><a href="/industry/convenience-stores" class="c-nav_dropdown-menu_item w-inline-block"><div class="c-nav_dropdown-menu_icon w-embed"><svg width="100%" height="100%" viewBox="0 0 32 32" fill="none" xmlns="http://www.w3.org/2000/svg">
<path d="M28.1333 12.9667H22.0667V11.6667H22.5C22.978 11.6667 23.3667 11.278 23.3667 10.8V3.86667C23.3667 3.3887 22.978 3 22.5 3H9.5C9.02203 3 8.63333 3.3887 8.63333 3.86667V10.8C8.63333 11.278 9.02203 11.6667 9.5 11.6667H9.93333V12.9667H3.86667C3.3887 12.9667 3 13.3554 3 13.8333V17.3C3 17.778 3.3887 18.1667 3.86667 18.1667V28.1333C3.86667 28.6113 4.25537 29 4.73333 29H27.2667C27.7446 29 28.1333 28.6113 28.1333 28.1333V18.1667C28.6113 18.1667 29 17.778 29 17.3V13.8333C29 13.3554 28.6113 12.9667 28.1333 12.9667ZM21.2 12.9667H19.9V11.6667H21.2V12.9667ZM19.0333 11.6667V12.9667H12.9667V11.6667H19.0333ZM9.5 3.86667H22.5L22.5009 10.8H9.5V3.86667ZM10.8 11.6667H12.1V12.9667H10.8V11.6667ZM28.1333 13.8333V15.1333H3.86667V13.8333H28.1333ZM10.8 28.1333H7.33333V21.2H10.8V28.1333ZM27.2667 28.1333H11.6667V21.2C11.6667 20.722 11.278 20.3333 10.8 20.3333H7.33333C6.85537 20.3333 6.46667 20.722 6.46667 21.2V28.1333H4.73333V18.1667H27.2667V28.1333ZM3.86667 17.3V16H28.1338V17.3H3.86667Z" fill="currentcolor"/>
<path d="M13.8335 25.1007H18.1668C18.6448 25.1007 19.0335 24.712 19.0335 24.234V21.2007C19.0335 20.7227 18.6448 20.334 18.1668 20.334H13.8335C13.3555 20.334 12.9668 20.7227 12.9668 21.2007V24.234C12.9668 24.712 13.3555 25.1007 13.8335 25.1007ZM13.8335 21.2007H18.1668L18.1677 24.234H13.8335V21.2007Z" fill="currentcolor"/>
<path d="M20.7671 25.1007H25.1004C25.5784 25.1007 25.9671 24.712 25.9671 24.234V21.2007C25.9671 20.7227 25.5784 20.334 25.1004 20.334H20.7671C20.2891 20.334 19.9004 20.7227 19.9004 21.2007V24.234C19.9004 24.712 20.2891 25.1007 20.7671 25.1007ZM20.7671 21.2007H25.1004L25.1013 24.234H20.7671V21.2007Z" fill="currentcolor"/>
<path d="M14.05 8.31176C14.7256 7.92219 15.5667 7.43642 15.5667 6.37389C15.5667 5.45349 14.8053 4.73242 13.8334 4.73242C12.6166 4.73242 12.1551 5.75682 12.136 5.80059C12.0411 6.01812 12.1399 6.26946 12.3561 6.36696C12.5724 6.46446 12.828 6.36696 12.9281 6.15202C12.9385 6.12949 13.192 5.59952 13.8329 5.59952C14.3269 5.59952 14.6996 5.93276 14.6996 6.37432C14.6996 6.90906 14.2879 7.17426 13.6163 7.56166C12.9407 7.95122 12.0996 8.43699 12.0996 9.49952C12.0996 9.73916 12.2937 9.93286 12.5329 9.93286H15.1329C15.3721 9.93286 15.5663 9.73916 15.5663 9.49952C15.5663 9.25989 15.3721 9.06619 15.1329 9.06619H13.0815C13.2479 8.78756 13.5872 8.57912 14.0496 8.31219L14.05 8.31176Z" fill="currentcolor"/>
<path d="M19.467 7.76717H19.0337V7.33384C19.0337 7.0942 18.84 6.9005 18.6004 6.9005C18.3607 6.9005 18.167 7.0942 18.167 7.33384V7.76717H17.4416L18.1506 5.2859C18.216 5.05624 18.083 4.81617 17.8524 4.7503C17.6249 4.68704 17.3827 4.81747 17.3168 5.04844L16.4502 8.08177C16.4129 8.21264 16.4393 8.35304 16.5208 8.4618C16.6027 8.57014 16.731 8.63384 16.867 8.63384H18.167V9.5005C18.167 9.74014 18.3607 9.93384 18.6004 9.93384C18.84 9.93384 19.0337 9.74014 19.0337 9.5005V8.63384H19.467C19.7067 8.63384 19.9004 8.44014 19.9004 8.2005C19.9004 7.96087 19.7067 7.76717 19.467 7.76717Z" fill="currentcolor"/>
</svg></div><div class="c-nav_text">Convenience</div></a><a href="/industry/sports-entertainment-venues" class="c-nav_dropdown-menu_item w-inline-block"><div class="c-nav_dropdown-menu_icon w-embed"><svg width="100%" height="100%" viewBox="0 0 32 32" fill="none" xmlns="http://www.w3.org/2000/svg">
<path d="M29.8795 10.2425C29.6864 9.46048 29.3099 8.73637 28.7499 8.09916C28.7499 8.09916 28.7499 8.09916 28.7403 8.08951C27.7169 7.02749 26.0466 6.05236 24.4825 5.59859C23.3916 5.23171 22.0206 5.03862 20.2827 5C20.2441 5 20.2152 5.00965 20.1765 5.01931C20.1476 5.00965 20.1186 5 20.0703 5H20.0317C19.9834 5 19.9255 5 19.8483 5C18.6511 5 17.4056 5.1062 16.1409 5.31861C15.7064 5.39584 14.8278 5.56963 14.3161 5.68548C13.4762 5.88823 12.6459 6.1296 11.8349 6.40959C10.0198 7.06611 8.12746 7.964 6.89166 8.74603C5.54966 9.53771 3.82146 11.1404 3.03943 12.3279C2.17051 13.612 1.79397 15.3402 2.11258 16.6146C2.17051 16.8367 2.24775 17.0684 2.34429 17.3001V17.3098V17.3194C2.50842 17.6284 2.71117 17.9373 2.94289 18.2366V19.6945C2.94289 19.7717 2.94289 19.8489 2.95254 19.9262V19.9358C2.97185 21.9923 4.07249 23.035 5.0283 23.7108C5.18278 23.8267 5.35656 23.9329 5.54 24.0487C5.56897 24.0681 6.25445 24.4639 6.48616 24.5798C7.33578 25.0142 8.27228 25.3618 9.26672 25.6128C9.29568 25.6225 10.0101 25.7962 10.3867 25.8542C11.4197 26.0376 12.53 26.1342 13.6789 26.1342H13.6982C13.8237 26.1342 14.461 26.1342 14.9727 26.0955C15.7354 26.0569 16.5271 25.97 17.3284 25.8542C17.618 25.8156 17.9077 25.7673 18.207 25.7094C18.2456 25.6997 19.0759 25.5452 19.4911 25.439C20.5724 25.188 21.5861 24.8694 22.5226 24.4929C22.5516 24.4832 23.3433 24.1453 23.6426 24.0005C24.6756 23.4888 25.6121 22.8998 26.4135 22.2337C26.4521 22.2047 27.0603 21.7026 27.4562 21.2585C28.8368 19.791 29.474 18.2849 29.4644 16.5084C29.474 16.3829 29.474 16.2477 29.474 16.1222V14.1237C29.474 14.0947 29.4644 14.0658 29.4547 14.0368C29.725 13.3803 29.9085 12.7431 29.9568 12.1831C29.9568 12.1831 29.9568 12.1831 29.9568 12.1734V12.1638C30.0243 11.739 30.0243 10.8025 29.8795 10.2425ZM29.5126 11.7776C28.8078 11.5073 27.5334 11.15 25.9983 11.3142C25.979 11.0535 25.9597 10.8121 25.9211 10.677C25.8052 10.2908 25.6025 9.93356 25.3032 9.61495C26.5583 8.7943 27.8424 8.57224 28.4603 8.50466C28.9237 9.06463 29.2327 9.68253 29.3968 10.3487C29.4837 10.6963 29.5126 11.2756 29.5126 11.7776ZM27.9679 15.8036C27.5141 15.1954 26.6162 14.2106 25.2163 13.5348C25.2742 13.4479 25.3225 13.361 25.3804 13.2741C25.3804 13.2644 25.3901 13.2644 25.3901 13.2548C25.6604 12.7817 25.9018 12.2603 25.979 11.8259C27.5624 11.6328 28.8561 12.0479 29.4837 12.3086C29.3389 13.3417 28.7692 14.6354 27.9679 15.8036ZM27.4755 20.5344V19.0186C27.9969 18.4876 28.4892 17.918 28.9623 17.3194C28.8079 18.478 28.3251 19.5207 27.4755 20.5344ZM26.1431 17.7346C26.1335 17.7442 26.1335 17.7442 26.1238 17.7539C25.757 18.0725 25.3611 18.3814 24.9653 18.6711C24.7143 18.0049 24.1253 16.7401 22.9185 15.6685C23.4495 15.2919 24.077 14.7995 24.5694 14.3168C24.5791 14.3071 24.5887 14.2975 24.5887 14.2975C24.7046 14.1816 24.8205 14.0658 24.917 13.9499C26.3652 14.6257 27.2631 15.6685 27.6589 16.2284C27.2631 16.7015 26.7321 17.2229 26.1431 17.7346ZM26.0466 19.6945C25.3418 20.3124 24.5984 20.8723 23.8164 21.3551V19.9551C24.2412 19.7234 24.6274 19.4917 24.9653 19.2697C25.3322 19.0186 25.6894 18.7483 26.0369 18.4587V19.6945H26.0466ZM23.3143 21.7992V23.6239C23.1405 23.7012 22.9088 23.8074 22.7157 23.8943V22.4074L22.7447 20.4958C22.9378 20.4089 23.1309 20.3124 23.3143 20.2158V21.7992ZM19.2207 23.5564V25.0142C18.9697 25.0721 18.6704 25.1301 18.4483 25.1783V23.8653V21.973C18.6028 21.944 18.7573 21.9054 18.9021 21.8764C19.0083 21.8475 19.1242 21.8185 19.2304 21.7895V23.5564H19.2207ZM14.7409 24.2418V25.6321C14.461 25.6418 14.1617 25.6514 13.9686 25.6514V24.2611V22.4654C14.2292 22.4654 14.4803 22.4557 14.7409 22.4461V24.2418ZM6.37031 22.5909V23.9522C6.21583 23.8653 6.0517 23.7688 5.9455 23.7108V22.0599V20.7179C6.08067 20.7854 6.22549 20.853 6.37031 20.9206V22.5909ZM2.88496 17.2325C3.51251 16.4794 4.72901 15.3692 6.46685 15.2726C6.51513 15.3885 6.5634 15.514 6.63098 15.6395C6.63098 15.6491 6.64064 15.6588 6.64064 15.6588C6.91097 16.1608 7.34543 16.7015 7.90541 17.107C6.4572 17.8794 5.71379 19.1731 5.40484 19.8489C4.28489 19.1345 3.35804 18.0628 2.88496 17.2325ZM8.18539 12.3376C8.76467 11.768 9.72049 11.1307 10.4832 10.6866C10.5894 10.7639 10.7342 10.8701 10.8791 10.9666C10.9273 10.9956 10.9756 11.0342 11.0142 11.0632C10.0198 11.5652 9.14121 12.1155 8.56193 12.5983C7.9923 13.0713 7.56749 13.6892 7.29716 14.4327C7.26819 14.423 7.22958 14.423 7.19096 14.4133C7.11372 14.394 7.02683 14.3844 6.94959 14.3651C7.11372 13.7472 7.55784 13.0134 8.18539 12.3376ZM11.497 10.1653C11.5452 10.2135 11.6032 10.2618 11.6611 10.3197C11.9218 10.5515 12.2211 10.8218 12.3369 10.9183C12.4528 11.0149 12.3466 10.9183 12.3466 10.928C12.4721 11.0149 12.6555 11.1694 12.839 11.3142C12.9162 11.3818 12.9934 11.4397 13.0707 11.4976L12.6266 11.7004C12.3659 11.4976 11.9121 11.1404 11.7094 10.9666L11.6514 10.9183C11.5645 10.8411 11.3714 10.7059 11.1687 10.5611C11.1011 10.5128 11.0335 10.4646 10.9659 10.4163C11.1301 10.3294 11.3135 10.2425 11.497 10.1653ZM13.9106 9.26738C14.2582 9.17083 14.5961 9.08394 14.9147 9.01636C15.6195 8.87154 16.6622 8.70741 17.3381 8.63017C17.676 8.59155 18.0042 8.56259 18.3228 8.54328C18.3228 8.56259 18.3132 8.5819 18.3132 8.60121C18.2842 8.72672 18.2553 8.87154 18.2263 8.9874C16.4015 9.12256 14.5478 9.59564 12.5397 10.4259C12.3948 10.3004 12.1728 10.1073 12.0087 9.94321C12.6748 9.67288 13.37 9.43151 13.9106 9.26738ZM19.3076 8.495C19.2787 8.57224 19.2497 8.64948 19.2207 8.71706C19.1338 8.93912 19.0759 9.08394 19.0566 9.15152C19.0083 9.27704 18.9504 9.46048 18.8828 9.65357C18.8249 9.8177 18.767 9.99148 18.7283 10.117C18.6221 10.117 18.5159 10.1267 18.4194 10.1267C18.4773 9.95287 18.5352 9.75977 18.5835 9.58599C18.6221 9.47013 18.6511 9.37358 18.6704 9.306V9.29635C18.6897 9.20945 18.7476 8.95843 18.8056 8.71706C18.8249 8.64948 18.8345 8.5819 18.8538 8.51431C18.9987 8.50466 19.1531 8.495 19.3076 8.495ZM19.9834 8.495H20.1765C21.171 8.52397 22.3875 8.73637 23.1019 8.91981C23.6136 9.07429 24.3377 9.47978 24.7625 9.78874C25.1004 10.088 25.3322 10.4356 25.448 10.8314C25.4577 10.8604 25.4673 10.9183 25.477 10.9763C24.0964 9.79839 22.1751 9.18049 20.7172 9.0067C20.3793 8.96809 20.0317 8.96809 19.6841 8.97774C19.6745 8.97774 19.6745 8.97774 19.6648 8.97774C19.6745 8.94878 19.6841 8.92947 19.6938 8.9005C19.7614 8.73637 19.8193 8.60121 19.8579 8.495C19.8869 8.48535 19.9352 8.495 19.9834 8.495ZM24.5405 6.1296C25.7666 6.51579 27.0893 7.2592 28.0162 8.0702C27.2148 8.19571 26.0563 8.51431 24.917 9.28669C24.5598 9.04532 23.9901 8.72672 23.4881 8.52397C23.8357 7.46195 24.2315 6.66061 24.5405 6.1296ZM22.4068 20.1C22.3971 20.1 22.3971 20.1096 22.3875 20.1096C21.9144 20.3317 21.422 20.5344 20.9296 20.7275C20.7944 19.9648 20.4855 18.5842 19.8772 17.2518C20.8234 16.856 21.8082 16.3636 22.484 15.9484C23.7584 17.0298 24.3281 18.3621 24.5405 18.9511C23.9419 19.3372 23.1985 19.7331 22.4068 20.1ZM18.7766 21.384C18.5835 21.4323 18.3711 21.4806 18.1491 21.5192C17.4732 21.6544 16.7298 21.7606 16.1602 21.8378C15.9961 21.0268 15.7836 19.6945 15.8126 18.3718C16.4691 18.2752 17.2898 18.1207 17.8111 17.9759C18.3518 17.8215 18.8925 17.638 19.4138 17.4449C20.0317 18.7773 20.331 20.1869 20.4565 20.9013C19.8966 21.0847 19.3366 21.2489 18.7766 21.384ZM13.9299 21.9633C12.8969 21.9633 11.6225 21.8282 10.7632 21.7123C10.7922 20.853 10.9853 19.4628 11.8735 18.3911C12.4142 18.449 13.2831 18.5166 13.8141 18.5166C14.3065 18.5166 14.8085 18.4876 15.3009 18.449C15.2816 19.7621 15.4844 21.0847 15.6485 21.9054C15.0692 21.9344 14.4899 21.9633 13.9299 21.9633ZM6.72753 20.5151C6.71788 20.5151 6.71788 20.5151 6.70822 20.5055C6.40893 20.3703 6.11928 20.2351 5.84895 20.1C6.12894 19.4628 6.89166 18.1014 8.43641 17.416C9.19914 17.7442 10.3287 18.1111 11.3039 18.2945C10.4929 19.4145 10.2901 20.7468 10.2612 21.6254C9.10259 21.4033 7.84748 20.9979 6.72753 20.5151ZM12.7135 12.2121L13.6596 11.768C15.1464 11.1307 16.6333 10.7542 18.0815 10.6384C18.0911 10.6384 18.5835 10.5997 18.8732 10.5997H18.9021C19.771 10.5997 20.582 10.6866 21.3351 10.8894C22.6675 11.2466 24.2798 12.1155 24.8784 13.1389C24.8011 13.2644 24.7239 13.3803 24.6467 13.4865C24.5598 13.5927 24.4632 13.6989 24.3474 13.8244L18.6801 11.2852C18.2746 11.0921 17.7918 11.1018 17.3863 11.2949L14.4513 12.7141L10.1646 14.7802C9.94255 14.8864 9.80738 15.0988 9.80738 15.3498C9.80738 15.5912 9.94255 15.8133 10.1646 15.9195L14.5478 18.0049C14.2968 18.0145 14.0458 18.0242 13.7948 18.0242C13.2445 18.0242 12.2886 17.947 11.7769 17.889C10.9273 17.7732 9.846 17.4546 9.0157 17.136C8.96742 17.078 8.89019 16.9139 8.83226 16.4698C8.83226 16.4408 8.8226 16.4215 8.8226 16.4119C8.78398 16.1995 8.78398 15.9774 8.8226 15.7553C8.8226 15.7457 8.8226 15.7457 8.8226 15.736C8.8226 15.736 8.8226 15.736 8.8226 15.7264C8.85157 15.3788 9.0157 15.1374 9.02535 15.1278C9.03501 15.1181 9.03501 15.1085 9.04466 15.0988C9.04466 15.0988 9.04466 15.0892 9.05432 15.0892C9.3343 14.5389 9.83635 14.0078 10.5605 13.5058C11.2556 13.0134 11.97 12.5789 12.7135 12.2121ZM17.8787 10.1556C16.4691 10.2908 15.0306 10.6577 13.592 11.2563C13.4762 11.1694 13.312 11.0342 13.1576 10.9183C13.0996 10.8701 13.0514 10.8314 12.9934 10.7832C14.7796 10.0687 16.4498 9.64391 18.0815 9.49909C18.0139 9.7115 17.9366 9.97218 17.8787 10.1556ZM19.4428 16.8946C18.8732 17.1167 18.2746 17.3194 17.6663 17.4932C17.1063 17.6573 16.2085 17.8118 15.5423 17.9083C15.5326 17.9083 15.5326 17.8987 15.523 17.8987L10.3867 15.4561C10.3384 15.4367 10.3094 15.3981 10.3094 15.3402C10.3094 15.2919 10.3384 15.2436 10.377 15.2243L14.5478 13.2162L20.6593 16.3539C20.2731 16.5374 19.8483 16.7305 19.4428 16.8946ZM8.01161 16.5567C7.98264 16.4408 7.95368 16.2284 7.9923 15.8422C8.11781 15.8615 8.22401 15.8809 8.32056 15.9002C8.3109 16.0933 8.32056 16.2864 8.34952 16.4698L8.35918 16.5084C8.36883 16.6146 8.38814 16.7208 8.41711 16.8367C8.27228 16.7498 8.13712 16.6629 8.01161 16.5567ZM10.2805 13.081C9.55636 13.583 9.03501 14.1237 8.70675 14.6933C8.504 14.6644 8.18539 14.6064 7.78955 14.5292C8.03092 13.9113 8.38814 13.3899 8.88053 12.9844C9.47912 12.4921 10.406 11.9224 11.4583 11.4011C11.6418 11.5459 11.9121 11.768 12.1342 11.9417C11.497 12.2797 10.8791 12.6658 10.2805 13.081ZM8.46538 15.1568C8.43641 15.234 8.40745 15.3112 8.38814 15.4078C8.23367 15.3788 8.04057 15.3498 7.81851 15.3112C7.77989 15.3016 7.74128 15.3112 7.70266 15.3209C7.68335 15.3112 7.66404 15.3112 7.63507 15.3112L7.00752 15.2919C6.95924 15.1857 6.91097 15.0795 6.88201 14.983C6.88201 14.9443 6.87235 14.9057 6.87235 14.8671C6.93028 14.8768 7.00752 14.8961 7.08476 14.9057C7.21992 14.9347 7.34543 14.954 7.39371 14.9637H7.40336C7.693 15.0119 8.12746 15.0988 8.46538 15.1568ZM7.49025 15.794C7.4806 15.8712 7.4806 15.9484 7.47094 16.016C7.41302 15.9388 7.35509 15.8615 7.29716 15.7843L7.49025 15.794ZM22.3585 15.4367C22.0496 15.6298 21.6634 15.8519 21.2289 16.074L15.1271 12.9362L17.618 11.739C17.8884 11.6135 18.207 11.6038 18.4773 11.739L23.9612 14.2009C23.5074 14.6064 22.9474 15.0506 22.3585 15.4367ZM25.1487 12.6465C24.3667 11.5749 22.7543 10.7542 21.4606 10.4066C20.7751 10.2232 20.0317 10.1267 19.2593 10.1073C19.2883 10.0108 19.3269 9.91425 19.3559 9.80805C19.3945 9.69219 19.4331 9.57633 19.4621 9.47979H19.6745C20.0028 9.47013 20.3407 9.47013 20.64 9.50875C22.5323 9.74046 24.415 10.5997 25.4866 11.7004C25.4577 11.9707 25.3225 12.3086 25.1487 12.6465ZM6.87235 21.1234C7.5868 21.413 8.34952 21.6737 9.10259 21.8764V23.3343C8.32056 23.0929 7.56749 22.8033 6.87235 22.4461V21.1234ZM9.60463 23.6626V21.9923C9.80738 22.0406 10.0101 22.0792 10.2032 22.1178V23.9136V25.3232C9.99082 25.2749 9.75911 25.2266 9.60463 25.188V23.6626ZM10.7053 22.2047C11.4583 22.3109 12.5107 22.4268 13.4569 22.4557V24.0101C12.501 23.9812 11.5838 23.8846 10.7053 23.7205V22.2047ZM15.243 22.4171C15.4844 22.3978 15.7354 22.3881 15.9767 22.3592C16.5078 22.3012 17.2415 22.195 17.9366 22.0695V23.6626C17.5408 23.7398 17.145 23.7977 16.7491 23.846C16.2471 23.9039 15.7354 23.9522 15.2333 23.9812V22.4171H15.243ZM19.7228 21.6544C20.0896 21.5482 20.4565 21.4323 20.8138 21.3068C21.2868 21.133 21.7696 20.9399 22.233 20.7275L22.204 22.2433C21.4027 22.6295 20.5724 22.9578 19.7131 23.2184V21.6544H19.7228ZM20.5241 5.50204C21.9434 5.54066 23.1019 5.70479 24.0481 5.98478C23.7391 6.5351 23.3529 7.33644 23.0054 8.3888C22.3006 8.22467 21.3254 8.06054 20.4372 8.01227C20.4662 6.95025 20.5048 6.10064 20.5241 5.50204ZM19.8676 5.49239H19.9352H19.9448H20.0028H20.0221C20.0028 6.08133 19.9641 6.9406 19.9352 7.99296C19.8193 7.99296 19.7035 7.99296 19.6745 7.99296C19.3655 7.99296 19.0373 8.00261 18.709 8.02192C18.6608 8.01227 18.6125 8.01227 18.5739 8.03158C18.2263 8.05089 17.8691 8.07985 17.5118 8.11847C17.2705 7.09507 16.9132 6.31304 16.614 5.76272C17.7146 5.57928 18.8152 5.49239 19.8676 5.49239ZM14.4513 6.16822C14.8858 6.06202 15.6099 5.9172 16.0733 5.8303C16.3726 6.342 16.7395 7.11438 17.0001 8.15709C16.3243 8.25364 15.4457 8.3888 14.8182 8.51431C14.5478 8.57224 14.2775 8.63983 13.9879 8.71706C13.6596 7.98331 13.1479 7.31713 12.4528 6.72819C13.1093 6.52544 13.7755 6.33235 14.4513 6.16822ZM11.8928 6.93094C12.6266 7.50057 13.1672 8.14744 13.4955 8.87154C12.8003 9.0936 12.0762 9.36393 11.439 9.64391H11.4294C11.1687 9.75977 10.9177 9.87563 10.6956 9.99148C9.93289 9.31565 8.96742 8.9005 7.86679 8.76534C8.99639 8.11847 10.4639 7.4523 11.8928 6.93094ZM7.11372 9.20945C8.00195 9.21911 9.20879 9.42186 10.2322 10.2425C9.49843 10.677 8.57158 11.2949 7.95368 11.8645C6.50547 11.2852 5.06692 11.5169 4.02421 11.8742C4.86417 10.899 6.10963 9.80805 7.11372 9.20945ZM3.43528 12.6658C4.48764 12.1638 6.02274 11.7197 7.5868 12.2603C6.9689 12.9941 6.40893 13.9499 6.37996 14.7706C4.63246 14.8864 3.387 15.9195 2.67255 16.7112C2.65324 16.6339 2.63393 16.5663 2.61463 16.4891C2.33464 15.3692 2.6629 13.8341 3.43528 12.6658ZM5.40484 20.4282C5.40484 20.4379 5.40484 20.4379 5.40484 20.4282C5.42415 20.4379 5.4338 20.4475 5.44345 20.4475V21.5771C4.70004 21.0558 4.03387 20.4668 3.46424 19.8296C3.46424 19.791 3.46424 19.7427 3.46424 19.7041V18.8352C4.04352 19.4724 4.72901 20.042 5.40484 20.4282ZM5.33725 23.315C4.54557 22.755 3.74423 22.0019 3.53182 20.6406C4.08214 21.2006 4.70004 21.7026 5.38553 22.1564C5.40484 22.1661 5.42415 22.1854 5.44345 22.195V23.3922C5.40484 23.3633 5.36622 23.3343 5.33725 23.315ZM6.87235 24.2129V22.9867C7.57714 23.3246 8.32056 23.6143 9.10259 23.8363V25.0528C8.3109 24.8404 7.56749 24.5604 6.87235 24.2129ZM10.7053 24.2225C11.5838 24.3867 12.5107 24.4735 13.4569 24.5025V25.6514C12.501 25.6418 11.5742 25.5549 10.7053 25.4197V24.2225ZM17.2898 25.3811C16.6043 25.4873 15.9092 25.5549 15.243 25.6031V24.4832C15.7643 24.4542 16.2953 24.4156 16.8264 24.348C17.2029 24.2998 17.5794 24.2418 17.9463 24.1743V25.2845C17.7242 25.3135 17.5022 25.3425 17.2898 25.3811ZM19.7228 23.7398C20.582 23.4888 21.4123 23.1702 22.2137 22.7936V24.1067C21.4413 24.406 20.6013 24.6763 19.7228 24.8984V23.7398ZM23.8164 23.3826V21.944C24.5887 21.4806 25.3322 20.9399 26.0466 20.351V21.9344C25.3901 22.4654 24.637 22.9481 23.8164 23.3826ZM26.5486 21.4999V19.8007V18.0339C26.6935 17.9083 26.8383 17.7732 26.9735 17.6477V18.9124V21.0751C26.8383 21.2296 26.6838 21.3744 26.5486 21.4999ZM29.0203 16.1319C29.0203 16.2284 29.0203 16.325 29.0106 16.4215C28.5375 17.078 28.0162 17.7056 27.4755 18.2945V17.2036C27.4755 17.1939 27.4755 17.1842 27.4755 17.1649C27.7362 16.8946 27.9679 16.6339 28.1706 16.3829C28.4892 15.9581 28.7692 15.5043 29.0203 15.0506V16.1319Z" fill="currentcolor"/>
</svg></div><div class="c-nav_text">Stadiums</div></a><a href="/industry/mini-markets-grab-n-go" class="c-nav_dropdown-menu_item w-inline-block"><div class="c-nav_dropdown-menu_icon w-embed"><svg width="100%" height="100%" viewBox="0 0 32 32" fill="none" xmlns="http://www.w3.org/2000/svg">
<path d="M7.9001 26.3999H7.03343C6.9185 26.3999 6.80828 26.4456 6.72702 26.5268C6.64575 26.6081 6.6001 26.7183 6.6001 26.8332C6.6001 26.9482 6.64575 27.0584 6.72702 27.1396C6.80828 27.2209 6.9185 27.2666 7.03343 27.2666H7.9001C8.01502 27.2666 8.12524 27.2209 8.20651 27.1396C8.28778 27.0584 8.33343 26.9482 8.33343 26.8332C8.33343 26.7183 8.28778 26.6081 8.20651 26.5268C8.12524 26.4456 8.01502 26.3999 7.9001 26.3999Z" fill="currentcolor"/>
<path d="M11.3669 26.3999H9.63353C9.5186 26.3999 9.40838 26.4456 9.32712 26.5268C9.24585 26.6081 9.2002 26.7183 9.2002 26.8332C9.2002 26.9482 9.24585 27.0584 9.32712 27.1396C9.40838 27.2209 9.5186 27.2666 9.63353 27.2666H11.3669C11.4818 27.2666 11.592 27.2209 11.6733 27.1396C11.7545 27.0584 11.8002 26.9482 11.8002 26.8332C11.8002 26.7183 11.7545 26.6081 11.6733 26.5268C11.592 26.4456 11.4818 26.3999 11.3669 26.3999Z" fill="currentcolor"/>
<path d="M12.9838 5.04031C13.0241 5.0001 13.0562 4.95233 13.0781 4.89971C13.1 4.8471 13.1113 4.79069 13.1113 4.7337C13.1114 4.67672 13.1002 4.62028 13.0784 4.56762C13.0567 4.51496 13.0247 4.46711 12.9844 4.42682L11.6844 3.12682C11.6032 3.04571 11.4932 3.0001 11.3785 3C11.2637 2.9999 11.1536 3.04531 11.0723 3.12628L8.50585 5.68332C8.11957 6.07042 7.90197 6.59452 7.90049 7.14138V9.68012C6.96316 9.94744 6.13001 10.4951 5.51284 11.2495C4.89566 12.0039 4.52399 12.929 4.44769 13.9007C4.3146 13.9607 4.20163 14.0577 4.12231 14.1803C4.04299 14.3028 4.0007 14.4456 4.00049 14.5916V15.9999C4.00049 16.1148 4.04614 16.2251 4.12741 16.3063C4.20867 16.3876 4.31889 16.4332 4.43382 16.4332H4.46264L5.30136 28.5964C5.3089 28.7059 5.35775 28.8085 5.43803 28.8834C5.51831 28.9583 5.62402 28.9999 5.73382 28.9999H12.6672C12.7769 28.9999 12.8826 28.9582 12.9628 28.8833C13.0431 28.8084 13.0919 28.7059 13.0995 28.5964L13.8187 18.1655V18.1631L13.9379 16.4332H13.9667C14.0816 16.4332 14.1919 16.3876 14.2731 16.3063C14.3544 16.2251 14.4001 16.1148 14.4001 15.9999V14.5916C14.3998 14.4456 14.3575 14.3028 14.2782 14.1803C14.1989 14.0577 14.0859 13.9607 13.9528 13.9007C13.8765 12.9291 13.5049 12.004 12.8878 11.2496C12.2708 10.4952 11.4377 9.94754 10.5005 9.68012V7.51345L12.9838 5.04031ZM11.3774 4.04532L12.0645 4.73243L10.1887 6.60064L9.73506 5.68192L11.3774 4.04532ZM9.08825 6.32953L9.36992 6.89991H8.79256C8.83745 6.68644 8.93968 6.48925 9.08825 6.32953ZM7.90049 10.5902V13.8332H5.32427C5.40694 13.1057 5.69225 12.416 6.14772 11.8426C6.60318 11.2693 7.21049 10.8353 7.90049 10.5902ZM13.5338 15.5666H4.86715V14.6999H13.5338V15.5666ZM8.76715 13.8332V10.3915C9.05509 10.3583 9.34589 10.3583 9.63382 10.3915V13.8332H8.76715ZM12.6989 21.8081L5.8616 24.1234L5.66048 21.2065L12.9096 18.7516L12.6989 21.8081ZM6.13818 28.1332L5.92341 25.0175L12.6343 22.745L12.2626 28.1332H6.13818ZM12.974 17.8149L5.59878 20.3124L5.33125 16.4332H13.0695L12.974 17.8149ZM13.0764 13.8332H10.5005V10.5902C11.1904 10.8354 11.7977 11.2693 12.2531 11.8427C12.7085 12.416 12.9938 13.1057 13.0764 13.8332ZM9.20049 9.49991C9.05424 9.49991 8.90994 9.5069 8.76715 9.51979V7.76657H9.63382V9.51984C9.49093 9.50689 9.34641 9.49991 9.20049 9.49991Z" fill="currentcolor"/>
<path d="M23.0769 3H21.3436C21.2286 3 21.1184 3.04565 21.0371 3.12692C20.9559 3.20819 20.9102 3.31841 20.9102 3.43333V8.2H17.8769C17.7802 8.2 17.6864 8.23231 17.6102 8.29179C17.534 8.35126 17.4799 8.43449 17.4565 8.52825L17.1052 9.93333H16.5769C16.462 9.93333 16.3517 9.97899 16.2705 10.0603C16.1892 10.1415 16.1436 10.2517 16.1436 10.3667V12.1C16.1436 12.2149 16.1892 12.3251 16.2705 12.4064C16.3517 12.4877 16.462 12.5333 16.5769 12.5333H16.7083L16.9019 15.1925V15.1932L17.878 28.5981C17.8859 28.7073 17.9349 28.8095 18.0151 28.884C18.0953 28.9586 18.2007 29 18.3102 29H26.5436C26.6541 29 26.7604 28.9578 26.8408 28.8819C26.9213 28.8061 26.9696 28.7024 26.9761 28.5921L27.9203 12.5262C28.0202 12.5083 28.1107 12.4557 28.1759 12.3778C28.2411 12.2999 28.2768 12.2016 28.2769 12.1V10.3667C28.2769 10.2517 28.2312 10.1415 28.15 10.0603C28.0687 9.97899 27.9585 9.93333 27.8436 9.93333H27.7485L27.3973 8.52825C27.3738 8.43449 27.3197 8.35126 27.2436 8.29179C27.1674 8.23231 27.0735 8.2 26.9769 8.2H23.5102V3.43333C23.5102 3.31841 23.4646 3.20819 23.3833 3.12692C23.302 3.04565 23.1918 3 23.0769 3ZM21.7769 3.86667H22.6436V8.2H21.7769V3.86667ZM17.0102 10.8H27.4102V11.6667H17.0102V10.8ZM26.5139 21.6837L18.5651 26.0998L18.4222 24.1372L26.638 19.5729L26.5139 21.6837ZM26.6046 12.5333L17.9282 17.3536L17.7853 15.391L22.9291 12.5333H26.6046ZM26.6982 18.548L18.3528 23.1843L18.2099 21.2217L26.8223 16.437L26.6982 18.548ZM26.8824 15.4123L18.1404 20.269L17.9975 18.3064L27.0064 13.3014L26.8824 15.4123ZM21.1447 12.5333L17.7159 14.4382L17.5772 12.5333H21.1447ZM18.6345 27.0526L26.4537 22.7084L26.3296 24.8193L20.3646 28.1333H18.7131L18.6345 27.0526ZM22.1492 28.1333L26.2694 25.8443L26.1349 28.1333H22.1492ZM26.8552 9.93333H17.9985L18.2152 9.06667H26.6386L26.8552 9.93333Z" fill="currentcolor"/>
</svg></div><div class="c-nav_text">Grab & Go</div></a><a href="/industry/higher-education" class="c-nav_dropdown-menu_item w-inline-block"><div class="c-nav_dropdown-menu_icon w-embed"><svg width="100%" height="100%" viewBox="0 0 32 32" fill="none" xmlns="http://www.w3.org/2000/svg">
<path d="M28.7358 10.062L16.1556 5.02993C16.0557 4.99002 15.9443 4.99002 15.8444 5.02993L3.26415 10.062C3.1862 10.0931 3.11936 10.1468 3.07226 10.2163C3.02517 10.2857 3 10.3677 3 10.4516C3 10.5355 3.02517 10.6175 3.07226 10.6869C3.11936 10.7564 3.1862 10.8101 3.26415 10.8412L15.8444 15.8733C15.9443 15.9132 16.0557 15.9132 16.1556 15.8733L23.3406 12.9991C23.4422 12.9567 23.523 12.876 23.5656 12.7745C23.6082 12.673 23.6091 12.5588 23.5683 12.4566C23.5275 12.3544 23.4481 12.2723 23.3472 12.2281C23.2464 12.1839 23.1323 12.1812 23.0294 12.2204L16 15.0321L4.5486 10.4516L16 5.87113L27.4514 10.4516L26.328 10.9007C26.2768 10.9212 26.2302 10.9515 26.1907 10.9899C26.1513 11.0284 26.1198 11.0742 26.0981 11.1248C26.0764 11.1755 26.0648 11.2299 26.0641 11.2849C26.0634 11.34 26.0736 11.3947 26.094 11.4459C26.1144 11.497 26.1447 11.5437 26.1832 11.5831C26.2216 11.6226 26.2675 11.654 26.3181 11.6758C26.3687 11.6975 26.4231 11.709 26.4782 11.7097C26.5333 11.7104 26.588 11.7003 26.6391 11.6799L28.7358 10.8412C28.8138 10.8101 28.8806 10.7564 28.9277 10.6869C28.9748 10.6175 29 10.5355 29 10.4516C29 10.3677 28.9748 10.2857 28.9277 10.2163C28.8806 10.1468 28.8138 10.0931 28.7358 10.062Z" fill="currentcolor"/>
<path d="M23.1282 13.8066C23.0169 13.8066 22.9103 13.8508 22.8316 13.9295C22.753 14.0081 22.7088 14.1148 22.7088 14.226V19.0535C20.7896 20.5434 18.429 21.3521 15.9993 21.3521C13.5697 21.3521 11.2091 20.5434 9.28986 19.0535V14.226C9.28986 14.1148 9.24568 14.0081 9.16703 13.9295C9.08839 13.8508 8.98173 13.8066 8.87051 13.8066C8.7593 13.8066 8.65264 13.8508 8.57399 13.9295C8.49535 14.0081 8.45117 14.1148 8.45117 14.226V19.2581C8.45117 19.3212 8.46543 19.3835 8.49287 19.4404C8.52032 19.4972 8.56025 19.5472 8.60968 19.5864C10.704 21.2716 13.3113 22.1903 15.9993 22.1903C18.6874 22.1903 21.2947 21.2716 23.389 19.5864C23.4384 19.5472 23.4783 19.4972 23.5058 19.4404C23.5332 19.3835 23.5475 19.3212 23.5475 19.2581V14.226C23.5475 14.1148 23.5033 14.0081 23.4247 13.9295C23.346 13.8508 23.2394 13.8066 23.1282 13.8066Z" fill="currentcolor"/>
<path d="M25.6459 18.0835V11.7933C25.6459 11.6958 25.6119 11.6014 25.5498 11.5262C25.4876 11.451 25.4012 11.3999 25.3054 11.3816L16.0799 9.62031C16.0254 9.60884 15.9691 9.60835 15.9144 9.61886C15.8597 9.62938 15.8076 9.65069 15.7613 9.68155C15.7149 9.71242 15.6751 9.75221 15.6443 9.79862C15.6134 9.84502 15.5922 9.8971 15.5817 9.95182C15.5712 10.0065 15.5718 10.0628 15.5833 10.1173C15.5948 10.1718 15.617 10.2235 15.6487 10.2693C15.6804 10.3151 15.721 10.3541 15.7679 10.3841C15.8149 10.4141 15.8673 10.4344 15.9222 10.4439L24.8073 12.1401V18.0835C23.8725 18.442 23.8042 19.6472 24.1682 20.5794L23.5522 25.9193C23.544 25.9924 23.5552 26.0664 23.5846 26.1338C23.614 26.2013 23.6607 26.2597 23.7199 26.3034C24.1554 26.6301 24.6851 26.8066 25.2295 26.8066C25.7739 26.8066 26.3036 26.6301 26.7392 26.3034C26.7984 26.2597 26.845 26.2013 26.8745 26.1338C26.9039 26.0664 26.9151 25.9924 26.9069 25.9193L26.285 20.579C26.649 19.6464 26.5802 18.4416 25.6459 18.0835ZM25.2266 18.8383C25.742 18.8383 25.6879 19.6602 25.544 20.1525C25.334 20.1873 25.1196 20.1873 24.9096 20.1525C24.7653 19.6598 24.7112 18.8383 25.2266 18.8383ZM24.4148 25.7574L24.9633 21.0025C25.138 21.0262 25.3152 21.0262 25.4899 21.0025L26.0384 25.7574C25.7893 25.8928 25.5102 25.9638 25.2266 25.9638C24.943 25.9638 24.6639 25.8928 24.4148 25.7574Z" fill="currentcolor"/>
</svg></div><div class="c-nav_text">Higher Ed</div></a><a href="/industry/healthcare" class="c-nav_dropdown-menu_item w-inline-block"><div class="c-nav_dropdown-menu_icon w-embed"><svg width="100%" height="100%" viewBox="0 0 32 32" fill="none" xmlns="http://www.w3.org/2000/svg">
<path d="M19.3332 16.6668H20.6665C20.8433 16.6668 21.0129 16.5966 21.1379 16.4716C21.2629 16.3465 21.3332 16.177 21.3332 16.0002C21.3332 15.8234 21.2629 15.6538 21.1379 15.5288C21.0129 15.4037 20.8433 15.3335 20.6665 15.3335H19.3332C19.1564 15.3335 18.9868 15.4037 18.8618 15.5288C18.7367 15.6538 18.6665 15.8234 18.6665 16.0002C18.6665 16.177 18.7367 16.3465 18.8618 16.4716C18.9868 16.5966 19.1564 16.6668 19.3332 16.6668Z" fill="currentcolor"/>
<path d="M4.59902 27.9985H27.399C27.5582 27.9985 27.7108 27.9353 27.8233 27.8228C27.9358 27.7103 27.999 27.5577 27.999 27.3985V12.9985C27.999 12.8394 27.9358 12.6868 27.8233 12.5743C27.7108 12.4617 27.5582 12.3985 27.399 12.3985H24.399V6.99853C24.399 6.83941 24.3358 6.68679 24.2233 6.57427C24.1108 6.46175 23.9582 6.39854 23.799 6.39854H20.799V5.79854C20.799 5.32115 20.6094 4.86331 20.2718 4.52574C19.9342 4.18818 19.4764 3.99854 18.999 3.99854H12.999C12.5216 3.99854 12.0638 4.18818 11.7262 4.52574C11.3887 4.86331 11.199 5.32115 11.199 5.79854V6.39854H8.19902C8.03989 6.39854 7.88728 6.46175 7.77476 6.57427C7.66224 6.68679 7.59902 6.83941 7.59902 6.99853V12.3985H4.59902C4.43989 12.3985 4.28728 12.4617 4.17476 12.5743C4.06224 12.6868 3.99902 12.8394 3.99902 12.9985V27.3985C3.99902 27.5577 4.06224 27.7103 4.17476 27.8228C4.28728 27.9353 4.43989 27.9985 4.59902 27.9985ZM24.399 13.5985H26.799V26.7985H24.399V13.5985ZM17.799 26.7985H14.199V22.5985H17.799V26.7985ZM12.399 5.79854C12.399 5.63941 12.4622 5.48679 12.5748 5.37427C12.6873 5.26175 12.8399 5.19854 12.999 5.19854H18.999C19.1582 5.19854 19.3108 5.26175 19.4233 5.37427C19.5358 5.48679 19.599 5.63941 19.599 5.79854V11.7985C19.599 11.9577 19.5358 12.1103 19.4233 12.2228C19.3108 12.3353 19.1582 12.3985 18.999 12.3985H12.999C12.8399 12.3985 12.6873 12.3353 12.5748 12.2228C12.4622 12.1103 12.399 11.9577 12.399 11.7985V5.79854ZM8.79902 7.59854H11.199V11.7985C11.199 12.2759 11.3887 12.7338 11.7262 13.0713C12.0638 13.4089 12.5216 13.5985 12.999 13.5985H18.999C19.4764 13.5985 19.9342 13.4089 20.2718 13.0713C20.6094 12.7338 20.799 12.2759 20.799 11.7985V7.59854H23.199V26.7985H18.999V21.9985C18.999 21.8394 18.9358 21.6868 18.8233 21.5743C18.7108 21.4617 18.5582 21.3985 18.399 21.3985H13.599C13.4399 21.3985 13.2873 21.4617 13.1748 21.5743C13.0622 21.6868 12.999 21.8394 12.999 21.9985V26.7985H8.79902V7.59854ZM5.19902 13.5985H7.59902V26.7985H5.19902V13.5985Z" fill="currentcolor"/>
<path d="M14.2001 9.3999H15.4001V10.5999C15.4001 10.759 15.4633 10.9116 15.5758 11.0242C15.6884 11.1367 15.841 11.1999 16.0001 11.1999C16.1592 11.1999 16.3118 11.1367 16.4244 11.0242C16.5369 10.9116 16.6001 10.759 16.6001 10.5999V9.3999H17.8001C17.9592 9.3999 18.1118 9.33669 18.2244 9.22417C18.3369 9.11164 18.4001 8.95903 18.4001 8.7999C18.4001 8.64077 18.3369 8.48816 18.2244 8.37564C18.1118 8.26312 17.9592 8.1999 17.8001 8.1999H16.6001V6.9999C16.6001 6.84077 16.5369 6.68816 16.4244 6.57564C16.3118 6.46312 16.1592 6.3999 16.0001 6.3999C15.841 6.3999 15.6884 6.46312 15.5758 6.57564C15.4633 6.68816 15.4001 6.84077 15.4001 6.9999V8.1999H14.2001C14.041 8.1999 13.8884 8.26312 13.7758 8.37564C13.6633 8.48816 13.6001 8.64077 13.6001 8.7999C13.6001 8.95903 13.6633 9.11164 13.7758 9.22417C13.8884 9.33669 14.041 9.3999 14.2001 9.3999Z" fill="currentcolor"/>
<path d="M11.7987 16.5999H12.9987C13.1579 16.5999 13.3105 16.5367 13.423 16.4242C13.5355 16.3116 13.5987 16.159 13.5987 15.9999C13.5987 15.8408 13.5355 15.6882 13.423 15.5756C13.3105 15.4631 13.1579 15.3999 12.9987 15.3999H11.7987C11.6396 15.3999 11.487 15.4631 11.3745 15.5756C11.2619 15.6882 11.1987 15.8408 11.1987 15.9999C11.1987 16.159 11.2619 16.3116 11.3745 16.4242C11.487 16.5367 11.6396 16.5999 11.7987 16.5999Z" fill="currentcolor"/>
<path d="M13.5987 18.9984C13.5987 18.8393 13.5355 18.6867 13.423 18.5742C13.3105 18.4617 13.1579 18.3984 12.9987 18.3984H11.7987C11.6396 18.3984 11.487 18.4617 11.3745 18.5742C11.2619 18.6867 11.1987 18.8393 11.1987 18.9984C11.1987 19.1576 11.2619 19.3102 11.3745 19.4227C11.487 19.5352 11.6396 19.5984 11.7987 19.5984H12.9987C13.1579 19.5984 13.3105 19.5352 13.423 19.4227C13.5355 19.3102 13.5987 19.1576 13.5987 18.9984Z" fill="currentcolor"/>
<path d="M15.3988 16.5999H16.5988C16.758 16.5999 16.9106 16.5367 17.0231 16.4242C17.1356 16.3116 17.1988 16.159 17.1988 15.9999C17.1988 15.8408 17.1356 15.6882 17.0231 15.5756C16.9106 15.4631 16.758 15.3999 16.5988 15.3999H15.3988C15.2397 15.3999 15.0871 15.4631 14.9746 15.5756C14.862 15.6882 14.7988 15.8408 14.7988 15.9999C14.7988 16.159 14.862 16.3116 14.9746 16.4242C15.0871 16.5367 15.2397 16.5999 15.3988 16.5999Z" fill="currentcolor"/>
<path d="M15.3988 19.5984H16.5988C16.758 19.5984 16.9106 19.5352 17.0231 19.4227C17.1356 19.3102 17.1988 19.1576 17.1988 18.9984C17.1988 18.8393 17.1356 18.6867 17.0231 18.5742C16.9106 18.4617 16.758 18.3984 16.5988 18.3984H15.3988C15.2397 18.3984 15.0871 18.4617 14.9746 18.5742C14.862 18.6867 14.7988 18.8393 14.7988 18.9984C14.7988 19.1576 14.862 19.3102 14.9746 19.4227C15.0871 19.5352 15.2397 19.5984 15.3988 19.5984Z" fill="currentcolor"/>
<path d="M18.9989 19.5984H20.1989C20.3581 19.5984 20.5107 19.5352 20.6232 19.4227C20.7357 19.3102 20.7989 19.1576 20.7989 18.9984C20.7989 18.8393 20.7357 18.6867 20.6232 18.5742C20.5107 18.4617 20.3581 18.3984 20.1989 18.3984H18.9989C18.8398 18.3984 18.6872 18.4617 18.5747 18.5742C18.4621 18.6867 18.3989 18.8393 18.3989 18.9984C18.3989 19.1576 18.4621 19.3102 18.5747 19.4227C18.6872 19.5352 18.8398 19.5984 18.9989 19.5984Z" fill="currentcolor"/>
</svg></div><div class="c-nav_text">Healthcare</div></a><a href="/industry/cafes-business-dining" class="c-nav_dropdown-menu_item w-inline-block"><div class="c-nav_dropdown-menu_icon w-embed"><svg width="100%" height="100%" viewBox="0 0 32 32" fill="none" xmlns="http://www.w3.org/2000/svg">
<path d="M12.3118 22.5824H4.74414C4.53705 22.5824 4.36914 22.4145 4.36914 22.2074V11.9956C4.36914 11.7885 4.53705 11.6206 4.74414 11.6206C5.42927 11.6206 6.073 11.8873 6.5567 12.3715C7.04064 12.855 7.30736 13.4987 7.30736 14.1838V20.328H11.0216C11.9398 20.328 12.6868 21.075 12.6868 21.9931V22.2073C12.6868 22.4145 12.5189 22.5824 12.3118 22.5824ZM5.11914 21.8324H11.9227C11.8465 21.4041 11.4715 21.078 11.0216 21.078H6.93236C6.72527 21.078 6.55736 20.9101 6.55736 20.703V14.1838C6.55736 13.6992 6.36878 13.2439 6.02636 12.9019C5.77412 12.6494 5.46058 12.4805 5.11914 12.4091V21.8324Z" fill="currentcolor"/>
<path d="M5.15188 27.6787C5.13528 27.6787 5.11855 27.6776 5.10163 27.6754C4.89636 27.6479 4.75222 27.4592 4.77973 27.2539L5.46355 22.148C5.49102 21.9427 5.67964 21.7988 5.885 21.8261C6.09027 21.8536 6.23441 22.0423 6.20689 22.2475L5.52308 27.3534C5.49786 27.5419 5.33684 27.6787 5.15188 27.6787Z" fill="currentcolor"/>
<path d="M12.0821 27.6787C11.9025 27.6787 11.7439 27.5494 11.7129 27.3664L10.8467 22.2605C10.812 22.0564 10.9494 21.8627 11.1536 21.828C11.3577 21.7937 11.5514 21.9309 11.5861 22.1351L12.4523 27.241C12.4869 27.4451 12.3495 27.6387 12.1453 27.6734C12.124 27.677 12.1029 27.6787 12.0821 27.6787Z" fill="currentcolor"/>
<path d="M27.3469 22.5824H19.7793C19.5722 22.5824 19.4043 22.4145 19.4043 22.2074V21.9931C19.4043 21.075 20.1513 20.328 21.0694 20.328H24.7837V14.1838C24.7837 13.4987 25.0503 12.855 25.5347 12.3713C26.018 11.8873 26.6618 11.6206 27.3469 11.6206C27.554 11.6206 27.7219 11.7885 27.7219 11.9956V22.2074C27.7219 22.4145 27.554 22.5824 27.3469 22.5824ZM20.1685 21.8324H26.9719V12.4091C26.6305 12.4805 26.317 12.6493 26.065 12.9016C25.7223 13.2439 25.5337 13.6991 25.5337 14.1838V20.7029C25.5337 20.91 25.3658 21.0779 25.1587 21.0779H21.0694C20.6197 21.078 20.2446 21.4041 20.1685 21.8324Z" fill="currentcolor"/>
<path d="M26.9432 27.6787C26.7582 27.6787 26.5972 27.5418 26.5719 27.3534L25.8881 22.2475C25.8607 22.0422 26.0047 21.8536 26.2101 21.8261C26.415 21.7988 26.604 21.9427 26.6315 22.148L27.3153 27.2539C27.3428 27.4592 27.1987 27.6478 26.9934 27.6754C26.9766 27.6776 26.9597 27.6787 26.9432 27.6787Z" fill="currentcolor"/>
<path d="M20.0108 27.6787C19.99 27.6787 19.9688 27.677 19.9476 27.6734C19.7434 27.6388 19.606 27.4451 19.6406 27.2409L20.5068 22.135C20.5414 21.9309 20.735 21.7937 20.9393 21.828C21.1434 21.8627 21.2809 22.0563 21.2463 22.2605L20.3801 27.3664C20.3491 27.5494 20.1903 27.6787 20.0108 27.6787Z" fill="currentcolor"/>
<path d="M21.7889 17.8333H10.1183C9.40876 17.8333 8.83154 17.2561 8.83154 16.5465C8.83154 15.837 9.40876 15.2598 10.1183 15.2598H21.7889C22.4984 15.2598 23.0756 15.837 23.0756 16.5465C23.0756 17.2561 22.4984 17.8333 21.7889 17.8333ZM10.1183 16.0098C9.82234 16.0098 9.58154 16.2506 9.58154 16.5465C9.58154 16.8425 9.82234 17.0833 10.1183 17.0833H21.7889C22.0848 17.0833 22.3256 16.8425 22.3256 16.5465C22.3256 16.2506 22.0848 16.0098 21.7889 16.0098H10.1183Z" fill="currentcolor"/>
<path d="M16.3151 19.8404H15.5857C14.9005 19.8404 14.2568 19.5737 13.7732 19.0894C13.3446 18.6615 13.0811 18.0934 13.0316 17.4903C13.0146 17.2839 13.1681 17.1027 13.3745 17.0858C13.5809 17.0685 13.7621 17.2223 13.779 17.4287C13.8141 17.8549 14.0003 18.2563 14.3035 18.5591C14.6458 18.9018 15.101 19.0904 15.5857 19.0904H16.3151C17.2516 19.0904 18.0451 18.3605 18.1219 17.4287C18.1389 17.2223 18.3205 17.069 18.5264 17.0858C18.7328 17.1028 18.8864 17.2839 18.8693 17.4903C18.7608 18.8081 17.6389 19.8404 16.3151 19.8404Z" fill="currentcolor"/>
<path d="M27.625 27.6816H4.375C4.16791 27.6816 4 27.5137 4 27.3066C4 27.0995 4.16791 26.9316 4.375 26.9316H27.625C27.8321 26.9316 28 27.0995 28 27.3066C28 27.5137 27.8321 27.6816 27.625 27.6816Z" fill="currentcolor"/>
<path d="M17.872 27.6815C17.8472 27.6815 17.8228 27.6791 17.7985 27.6745C17.7746 27.6693 17.7511 27.6623 17.7286 27.6529C17.7056 27.6436 17.6841 27.6318 17.6635 27.6187C17.6433 27.6046 17.624 27.5892 17.6067 27.5718C17.5894 27.5545 17.5735 27.5353 17.5599 27.5151C17.5467 27.4945 17.535 27.4729 17.5256 27.45C17.5163 27.4275 17.5088 27.404 17.5041 27.3801C17.4994 27.3557 17.4966 27.3314 17.4966 27.3065C17.4966 27.2821 17.4994 27.2578 17.5041 27.2334C17.5088 27.2095 17.5163 27.1861 17.5256 27.1631C17.535 27.1406 17.5467 27.119 17.5599 27.0984C17.5735 27.0778 17.5894 27.0585 17.6067 27.0417C17.624 27.0243 17.6433 27.0084 17.6635 26.9948C17.684 26.9812 17.7056 26.97 17.7286 26.9606C17.7511 26.9512 17.7746 26.9437 17.7985 26.939C17.8467 26.9292 17.8969 26.9292 17.9452 26.939C17.9691 26.9437 17.9925 26.9512 18.0155 26.9606C18.0379 26.97 18.0595 26.9812 18.0802 26.9948C18.1003 27.0084 18.1196 27.0243 18.1369 27.0417C18.1542 27.0585 18.1702 27.0778 18.1838 27.0984C18.1974 27.119 18.2086 27.1405 18.218 27.1631C18.2273 27.1861 18.2348 27.2095 18.2396 27.2334C18.2442 27.2578 18.2465 27.2821 18.2465 27.3065C18.2465 27.3314 18.2442 27.3557 18.2396 27.3801C18.2348 27.404 18.2273 27.4275 18.218 27.45C18.2086 27.4729 18.1974 27.4944 18.1838 27.5151C18.1702 27.5353 18.1542 27.5545 18.1369 27.5718C18.1196 27.5892 18.1003 27.6046 18.0802 27.6187C18.0595 27.6318 18.038 27.6436 18.015 27.6529C17.9925 27.6623 17.9691 27.6693 17.9452 27.6745C17.9208 27.6791 17.8964 27.6815 17.872 27.6815Z" fill="currentcolor"/>
<path d="M18.9606 11.3176H13.049C12.7686 11.3176 12.5234 11.1379 12.4391 10.8704C12.3598 10.6185 12.4417 10.3487 12.6433 10.1838L15.4846 7.10076L15.5323 4.37137C15.5359 4.16652 15.7031 4.00293 15.9071 4.00293C15.9094 4.00293 15.9116 4.00293 15.9138 4.00298C16.1209 4.00663 16.2859 4.1774 16.2822 4.38449L16.2348 7.09602L19.3435 10.166C19.5576 10.3252 19.6503 10.5969 19.5745 10.857C19.4943 11.1324 19.2475 11.3176 18.9606 11.3176ZM13.3094 10.5676H18.6829L15.8697 7.78949L13.3094 10.5676Z" fill="currentcolor"/>
<path d="M15.9551 27.6779C15.748 27.6779 15.5801 27.5099 15.5801 27.3029V19.644C15.5801 19.4369 15.748 19.269 15.9551 19.269C16.1622 19.269 16.3301 19.4369 16.3301 19.644V27.3029C16.3301 27.5099 16.1622 27.6779 15.9551 27.6779Z" fill="currentcolor"/>
</svg></div><div class="c-nav_text">Business Dining</div></a><a href="/industry/ski-resorts" class="c-nav_dropdown-menu_item w-inline-block"><div class="c-nav_dropdown-menu_icon w-embed"><svg width="100%" height="100%" viewBox="0 0 32 32" fill="none" xmlns="http://www.w3.org/2000/svg">
<path d="M24.3943 4.00002C23.5384 3.99709 22.7284 4.38702 22.1971 5.05814C21.6659 5.72907 21.472 6.60687 21.6712 7.43927C20.5157 6.72715 19.0358 6.82472 17.9837 7.68238L15.2331 9.91707L10.7541 7.78362L10.9573 7.37813C11.0559 7.18042 10.9757 6.94023 10.778 6.84138C10.5803 6.74271 10.3401 6.82289 10.2413 7.0206L10.0306 7.43927L8.76962 6.83937C8.63946 6.76541 8.47891 6.77017 8.35351 6.852C8.22811 6.93383 8.15891 7.07863 8.17411 7.22765C8.1893 7.37648 8.28633 7.50444 8.42582 7.55918L9.67268 8.15305L9.43946 8.61895C9.34079 8.81666 9.42097 9.05702 9.61868 9.1557C9.81639 9.25437 10.0566 9.17419 10.1554 8.97647L10.3952 8.49666L14.5452 10.4747L13.8466 11.0422C13.6029 11.2412 13.3968 11.4823 13.2383 11.7539C12.679 12.9323 13.0675 14.3427 14.1512 15.0684L17.9506 17.5015L14.0086 19.2543C13.3525 19.5368 12.9519 20.2081 13.0147 20.9195L8.00624 17.8654C7.88413 17.7893 7.73072 17.7845 7.60422 17.853C7.47773 17.9214 7.39773 18.0525 7.39461 18.1962C7.39169 18.3401 7.46601 18.4743 7.58958 18.5481L22.2791 27.5062C23.4484 28.2253 24.9389 28.1539 26.034 27.3262C26.2107 27.1937 26.2464 26.9429 26.1138 26.7663C25.9815 26.5896 25.7307 26.5537 25.554 26.6863C24.72 27.3156 23.5857 27.3698 22.6954 26.823L15.1667 22.2313C15.1927 22.2213 15.2207 22.2169 15.2467 22.2054L20.8719 19.7038C21.9829 19.2031 22.4944 17.9097 22.0267 16.7844C21.8531 16.3676 21.5557 16.0139 21.1745 15.7715L18.1704 13.652L19.2102 13.1321L20.6167 14.1102L21.8564 14.9737C22.4629 15.4089 23.2856 15.384 23.8649 14.9129L25.2245 15.5595C25.3535 15.621 25.5055 15.6089 25.6232 15.5278C25.7409 15.4469 25.8064 15.3093 25.7951 15.1668C25.7839 15.0242 25.6973 14.8987 25.5685 14.8373L24.3234 14.2446C24.4184 13.9936 24.4477 13.7226 24.4087 13.4572C24.3417 13.0237 24.1005 12.6365 23.7407 12.3853L22.6746 11.6452L22.7947 11.6199C23.2263 11.5266 23.5006 11.1011 23.4072 10.6695L23.1674 9.56357C23.1458 9.46361 23.1121 9.36805 23.0817 9.27121C24.1105 9.81821 25.3704 9.67066 26.2451 8.90105C27.1198 8.13126 27.4262 6.90033 27.0145 5.81035C26.603 4.72056 25.5593 3.99947 24.3943 4.00002ZM23.2818 13.0413C23.4621 13.1667 23.5829 13.3609 23.6159 13.5782C23.6487 13.7953 23.5908 14.0166 23.4557 14.1898C23.1668 14.5232 22.6704 14.5788 22.3147 14.3178L21.3437 13.6419L20.7575 13.234L19.4705 12.339H19.4685L19.1019 12.0838C18.9354 11.9683 18.819 11.7937 18.7764 11.5956L18.6231 10.8849C18.5779 10.6775 18.6171 10.4606 18.7321 10.2821C18.8468 10.1036 19.0279 9.97803 19.2353 9.93318L20.0468 9.75762C20.2627 9.71093 20.4 9.49821 20.3533 9.28238C20.3068 9.06636 20.0939 8.92906 19.878 8.97574L19.0667 9.1513C18.2037 9.33876 17.6553 10.1891 17.8405 11.0524L17.9936 11.7635C18.0652 12.0864 18.2352 12.3789 18.4803 12.601L17.6602 13.0116C17.6132 13.0352 17.5712 13.0676 17.5366 13.1072C17.3838 13.2838 17.3157 13.5182 17.3503 13.7492C17.3819 13.9729 17.5084 14.1722 17.6974 14.2962L20.7311 16.4373C20.981 16.5937 21.1765 16.8234 21.291 17.0953C21.5912 17.8185 21.2624 18.6497 20.5483 18.9715L14.9215 21.4762C14.7207 21.5654 14.4923 21.5681 14.2894 21.4837C14.0866 21.3993 13.9275 21.2353 13.8493 21.0299C13.7137 20.6092 13.9248 20.155 14.3337 19.9873L18.2757 18.2321C18.5442 18.1126 18.7255 17.855 18.7476 17.5617C18.7698 17.2684 18.6292 16.9867 18.3815 16.828L14.5823 14.395C13.8513 13.8965 13.5806 12.947 13.9388 12.1378C14.0476 11.9568 14.1871 11.7961 14.3513 11.6631L18.488 8.30389C19.4411 7.52513 20.8296 7.59653 21.6977 8.46902C22.0446 8.81538 22.2839 9.25473 22.3868 9.734L22.6266 10.8397L22.0591 10.9598C21.8253 11.0098 21.6434 11.1941 21.5965 11.4286C21.5496 11.6633 21.6465 11.9033 21.8433 12.0395L23.2818 13.0413ZM24.3943 8.7989C23.29 8.7989 22.3947 7.90371 22.3947 6.79946C22.3947 5.69502 23.29 4.79983 24.3943 4.79983C25.4985 4.79983 26.3939 5.69502 26.3939 6.79946C26.3924 7.90316 25.498 8.79762 24.3943 8.7989Z" fill="currentcolor"/>
<path d="M8.59963 15.1958C8.77812 15.196 8.93501 15.0779 8.98444 14.9064C9.03368 14.7349 8.96338 14.5514 8.81199 14.4568L5.61273 12.4571C5.42491 12.3402 5.17777 12.3975 5.06079 12.5851C4.94363 12.7729 5.00093 13.0201 5.18875 13.1371L8.38801 15.1367C8.45172 15.1757 8.52494 15.1962 8.59963 15.1958Z" fill="white"/>
<path d="M7.98763 13.137L11.1869 15.1366C11.3745 15.2536 11.6217 15.1963 11.7386 15.0087C11.8558 14.8208 11.7985 14.5739 11.6107 14.4567L8.41143 12.4573C8.22379 12.3401 7.97665 12.3974 7.85949 12.5852C7.74251 12.7729 7.79981 13.02 7.98763 13.137Z" fill="currentcolor"/>
</svg></div><div class="c-nav_text">Ski Resorts</div></a></div></div></nav></div><div data-delay="0" data-hover="true" class="c-nav_dropdown w-dropdown"><div class="c-nav_dropdown-toggle w-dropdown-toggle"><div class="c-nav_text">Resources</div><div class="c-icon cc-xs w-embed"><svg width="100%" height="100%" viewBox="0 0 13 8" fill="none" xmlns="http://www.w3.org/2000/svg">
<path d="M1.104 1.5L6.104 6.5L11.104 1.5" stroke="currentcolor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"/>
</svg></div></div><nav class="c-nav_dropdown-menu_wrap cc-resources w-dropdown-list"><div id="nav-scrollable" class="c-nav_dropdown-menu"><div class="c-wrap cc-z_1 cc-width_100 cc-gap_0"><a href="/content/mashgin-case-studies" class="c-nav_dropdown-menu_item w-inline-block"><div class="c-nav_text">Case Studies</div></a><a href="/skip-the-line-podcast" class="c-nav_dropdown-menu_item w-inline-block"><div class="c-nav_text">Podcast</div></a><a href="/resources/news" class="c-nav_dropdown-menu_item w-inline-block"><div class="c-nav_text">News</div></a><a href="https://blog.mashgin.com/ai-retail" target="_blank" class="c-nav_dropdown-menu_item w-inline-block"><div class="c-nav_text">Blog</div></a><a href="/resources/faq" class="c-nav_dropdown-menu_item w-inline-block"><div class="c-nav_text">FAQs</div></a></div></div></nav></div><div data-delay="0" data-hover="true" class="c-nav_dropdown w-dropdown"><div class="c-nav_dropdown-toggle w-dropdown-toggle"><div class="c-nav_text">Support</div><div class="c-icon cc-xs w-embed"><svg width="100%" height="100%" viewBox="0 0 13 8" fill="none" xmlns="http://www.w3.org/2000/svg">
<path d="M1.104 1.5L6.104 6.5L11.104 1.5" stroke="currentcolor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"/>
</svg></div></div><nav class="c-nav_dropdown-menu_wrap cc-support w-dropdown-list"><div id="nav-scrollable" class="c-nav_dropdown-menu"><div class="c-wrap cc-z_1 cc-width_100 cc-gap_0"><a href="https://mashgin.service-now.com/kb" target="_blank" class="c-nav_dropdown-menu_item w-inline-block"><div class="c-nav_text">Knowledge Base</div></a><a href="/content/mashgin-university" class="c-nav_dropdown-menu_item w-inline-block"><div class="c-nav_text">Mashgin University</div></a></div></div></nav></div></div><div class="c-wrap cc-horizontal cc-mobile_lands-vertical cc-z_3"><a href="https://cloud.mashgin.com/login" target="_blank" class="c-button cc-transparent w-inline-block"><div class="c-button_text">Customer Sign In</div><div class="c-button_arrow w-embed"><svg width="100%" height="100%" viewBox="0 0 24 24" fill="none" xmlns="http://www.w3.org/2000/svg">
<path d="M2.78125 12L20.7812 12" stroke="currentcolor" stroke-width="2" stroke-linejoin="round"/>
<path d="M14.2188 5L21.2188 12L14.2188 19" stroke="currentcolor" stroke-width="2" stroke-linejoin="round"/>
</svg></div></a><a href="/contact" class="c-button cc-gradient w-inline-block"><div class="c-button_text">Request Demo</div><div class="c-button_arrow w-embed"><svg width="100%" height="100%" viewBox="0 0 24 24" fill="none" xmlns="http://www.w3.org/2000/svg">
<path d="M2.78125 12L20.7812 12" stroke="currentcolor" stroke-width="2" stroke-linejoin="round"/>
<path d="M14.2188 5L21.2188 12L14.2188 19" stroke="currentcolor" stroke-width="2" stroke-linejoin="round"/>
</svg></div></a></div></div></nav><div id="menu-button" class="c-nav_menu-button w-nav-button"><div data-is-ix2-target="1" class="c-nav_menu-button_icon" data-w-id="e677754d-587f-275b-2766-46bbb3c92e63" data-animation-type="lottie" data-src="https://cdn.prod.website-files.com/6466446d7f241c12327f2c4b/6485a47731e8ac270486c0e3_42428-menu%20(4).json" data-loop="0" data-direction="1" data-autoplay="0" data-renderer="svg" data-default-duration="2.566666666666667" data-duration="0"></div></div></div></div><div class="c-nav_overlay"></div><div class="w-embed"><style>
/* 1) Default: closed -> white */
.c-nav_dropdown-toggle .c-nav_text,
.c-nav_dropdown-toggle .c-icon {
color: #FFFFFF;
}
/* 2) Open state: Webflow adds w--open on the TOGGLE itself */
.c-nav_dropdown-toggle.w--open .c-nav_text {
background: linear-gradient(90deg, #45C7AB 0%, #63E14F 74%);
-webkit-background-clip: text;
background-clip: text;
-webkit-text-fill-color: transparent;
color: transparent; /* fallback */
}
/* icon (SVG uses currentColor) – use a solid that matches the gradient end */
.c-nav_dropdown-toggle.w--open .c-icon {
color: #63E14F;
}
/* 3) Extra safety: if for some reason only the LIST gets w--open */
.c-nav_dropdown:has(> .c-nav_dropdown-menu_wrap.w--open) .c-nav_dropdown-toggle .c-nav_text {
background: linear-gradient(90deg, #45C7AB 0%, #63E14F 74%);
-webkit-background-clip: text;
background-clip: text;
-webkit-text-fill-color: transparent;
color: transparent;
}
.c-nav_dropdown:has(> .c-nav_dropdown-menu_wrap.w--open) .c-nav_dropdown-toggle .c-icon {
color: #63E14F;
}
</style></div></div><section class="c-section"><div class="c-container"><div id="w-node-_8b792325-0839-ccf7-5948-c771823e2b80-2c429536" class="c-wrap cc-width_70"><h1 class="c-text_xxl">Data Processing Addendum </h1><p class="c-paragraph_l">Effective date: 01 November 2025<br/>Last Reviewed: 01 November 2025</p><div class="c-rich-text w-richtext"><p>This Data Processing Addendum (“DPA”) supplements the Master Services and Equipment Agreement (the “Agreement”) entered into by and between Customer and Mashgin, Inc (henceforth “Mashgin”). By entering into the Agreement, when required by applicable Data Protection Laws (defined below), Customer enters into this DPA on behalf of itself and on behalf of its Affiliates (defined below), if any. This DPA incorporates the terms of the Agreement, and any terms not defined in this DPA shall have the meaning set forth in the Agreement. </p><h2><strong>1.</strong> <strong>Definitions</strong></h2><p>1.1 “Affiliate” means (i) an entity of which a party directly or indirectly owns fifty percent (50%) or more of the stock or other equity interest, (ii) an entity that owns at least fifty percent (50%) or more of the stock or other equity interest of a party, or (iii) an entity which is under common control with a party by having at least fifty percent (50%) or more of the stock or other equity interest of such entity and a party owned by the same person, but such entity shall only be deemed to be an Affiliate so long as such ownership exists.</p><p>1.2 “Authorized Sub-Processor” means a third-party who has a need to know or otherwise access Customer’s Personal Data to enable Mashgin to perform its obligations under this DPA or the Agreement, and who is either (1) listed in Exhibit B or (2) subsequently authorized under Section 4.2 of this DPA.</p><p>1.3 “Data Exporter” means Customer.</p><p>1.4 “Data Importer” means Mashgin.</p><p>1.5 “Data Protection Laws” means any applicable laws and regulations in any relevant jurisdiction relating to the use or processing of Personal Data including: (i) the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 (“CCPA”), (ii) the General Data Protection Regulation (Regulation (EU) 2016/679) (“EU GDPR”) and the EU GDPR as it forms part of the law of England and Wales by virtue of section 3 of the European Union (Withdrawal) Act 2018 (the “UK GDPR”) (together, collectively, the “GDPR”), (iii) the Swiss Federal Act on Data Protection, (iv) the UK Data Protection Act 2018, (v) the Privacy and Electronic Communications (EC Directive) Regulations 2003, (vi) the Virginia Consumer Data Protection Act (“VCDPA”), (vii) the Colorado Privacy Act (“CPA”), (viii) the Connecticut Data Privacy Act (“CTDPA”), (ix) the Utah Consumer Privacy Act (“UCPA”); and (x) the Washington My Health My Data Act (“MHMDA”), in each case, as updated, amended or replaced from time to time. The terms “Data Subject”, “Personal Data”, “Personal Data Breach”, “processing”, “processor,” “controller,” and “supervisory authority” shall have the meanings set forth in the GDPR. </p><p>1.6 “EU SCCs” means the standard contractual clauses approved by the European Commission in Commission Decision 2021/914 dated 4 June 2021, for transfers of personal data to countries not otherwise recognized as offering an adequate level of protection for personal data by the European Commission (as amended and updated from time to time), as modified by Section 6.2 of this DPA.</p><p>1.7 “ex-EEA Transfer” means the transfer of Personal Data, which is processed in accordance with the GDPR, from the Data Exporter to the Data Importer (or its premises) outside the European Economic Area (the “EEA”), and such transfer is not governed by an adequacy decision made by the European Commission in accordance with the relevant provisions of the GDPR.</p><p>1.8 “ex-UK Transfer” means the transfer of Personal Data covered by Chapter V of the UK GDPR, which is processed in accordance with the UK GDPR and the Data Protection Act 2018, from the Data Exporter to the Data Importer (or its premises) outside the United Kingdom (the “UK”), and such transfer is not governed by an adequacy decision made by the Secretary of State in accordance with the relevant provisions of the UK GDPR and the Data Protection Act 2018.</p><p>1.9 “Mashgin Account Data” means personal data that relates to Mashgin’s relationship with Customer, including the names or contact information of individuals authorized by Customer to access Customer’s account and billing information of individuals that Customer has associated with its account. Mashgin Account Data also includes any data Mashgin may need to collect for the purpose of managing its relationship with Customer, identity verification, or as otherwise required by applicable laws and regulations.</p><p>1.10 “Mashgin Usage Data” means Service usage data collected and processed by Mashgin in connection with the provision of the Services, including without limitation data used to identify the source and destination of a communication, activity logs, and data used to optimize and maintain performance of the Services, and to investigate and prevent system abuse.</p><p>1.11 “Services” shall have the meaning set forth in the Agreement.</p><p>1.12 “Standard Contractual Clauses” means the EU SCCs and the UK SCCs. </p><p>1.13 “UK Addendum” has the meaning set forth in Exhibit D.</p><p>1.14 “UK SCCs” means the EU SCCs, as amended by the UK Addendum. </p><h2><strong>2.</strong> <strong>Relationship of the Parties; Processing of Data</strong></h2><p>2.1 The parties acknowledge and agree that with regard to the processing of Personal Data, Customer may act either as a controller or processor and, except as expressly set forth in this DPA or the Agreement, Mashgin is a processor. Customer shall, in its use of the Services, at all times process Personal Data, and provide instructions for the processing of Personal Data, in compliance with Data Protection Laws. Customer shall ensure that the processing of Personal Data in accordance with Customer’s instructions will not cause Mashgin to be in breach of the Data Protection Laws. Customer is solely responsible for the accuracy, quality, and legality of (i) the Personal Data provided to Mashgin by or on behalf of Customer, (ii) the means by which Customer acquired any such Personal Data, and (iii) the instructions it provides to Mashgin regarding the processing of such Personal Data. Customer shall not provide or make available to Mashgin any Personal Data in violation of the Agreement or otherwise inappropriate for the nature of the Services, and shall indemnify Mashgin from all claims and losses in connection therewith.</p><p>2.2 Mashgin shall not process Personal Data (i) for purposes other than those set forth in the Agreement and/or Exhibit A, (ii) in a manner inconsistent with the terms and conditions set forth in this DPA or any other documented instructions provided by Customer, including with regard to transfers of personal data to a third country or an international organization, unless required to do so by Supervisory Authority to which Mashgin is subject; in such a case, Mashgin shall inform the Customer of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest, or (iii) in violation of Data Protection Laws. Customer hereby instructs Mashgin to process Personal Data in accordance with the foregoing and as part of any processing initiated by Customer in its use of the Services.</p><p>2.3 The subject matter, nature, purpose, and duration of this processing, as well as the types of Personal Data collected and categories of Data Subjects, are described in Exhibit A to this DPA.</p><p>2.4 Following completion of the Services, at Customer’s choice, Mashgin shall return or delete Customer’s Personal Data, unless further storage of such Personal Data is required or authorized by applicable law. If return or destruction is impracticable or prohibited by law, rule or regulation, Mashgin shall take measures to block such Personal Data from any further processing (except to the extent necessary for its continued hosting or processing required by law, rule or regulation) and shall continue to appropriately protect the Personal Data remaining in its possession, custody, or control. If Customer and Mashgin have entered into Standard Contractual Clauses as described in Section 6 (Transfers of Personal Data), the parties agree that the certification of deletion of Personal Data that is described in Clause 8.1(d) and Clause 8.5 of the EU SCCs (as applicable) shall be provided by Mashgin to Customer only upon Customer’s request. </p><p>2.5 The Parties acknowledge and agree that the processing of personal information or personal data that is subject to the CCPA, VCDPA, CPA, CTDPA, UCPA, or MHMDA shall be carried out in accordance with the terms set forth in Exhibit E.</p><h2><strong>3.</strong> <strong>Confidentiality</strong></h2><p>Mashgin shall ensure that any person it authorizes to process Personal Data has agreed to protect Personal Data in accordance with Mashgin’s confidentiality obligations in the Agreement. Customer agrees that Mashgin may disclose Personal Data to its advisers, auditors or other third parties as reasonably required in connection with the performance of its obligations under this DPA, the Agreement, or the provision of Services to Customer. </p><h2><strong>4.</strong> <strong>Authorized Sub-Processors</strong></h2><p>4.1 Customer acknowledges and agrees that Mashgin may (1) engage its Affiliates and the Authorized Sub-Processors listed in Exhibit B to this DPA to access and process Personal Data in connection with the Services and (2) from time to time engage additional third parties for the purpose of providing the Services, including without limitation the processing of Personal Data. By way of this DPA, Customer provides general written authorization to Mashgin to engage sub-processors as necessary to perform the Services.</p><p>4.2 A list of Mashgin’s current Authorized Sub-Processors (the “List”) will be made available to Customer, either attached hereto, at a link provided to Customer, via email or through another means made available to Customer. Such List may be updated by Mashgin from time to time. Mashgin may provide a mechanism to subscribe to notifications of new Authorized Sub-Processors and Customer agrees to subscribe to such notifications where available. At least ten (10) days before enabling any third party other than existing Authorized Sub-Processors to access or participate in the processing of Personal Data, Mashgin will add such third party to the List and notify Customer via email. Customer may object to such an engagement by informing Mashgin within ten (10) days of receipt of the aforementioned notice by Customer, provided such objection is in writing and based on reasonable grounds relating to data protection. Customer acknowledges that certain sub-processors are essential to providing the Services and that objecting to the use of a sub-processor may prevent Mashgin from offering the Services to Customer.</p><p>4.3 If Customer reasonably objects to an engagement in accordance with Section 4.2, and Mashgin cannot provide a commercially reasonable alternative within a reasonable period of time, Customer may discontinue the use of the affected Service by providing written notice to Mashgin. Discontinuation shall not relieve Customer of any fees owed to Mashgin under the Agreement.</p><p>4.4 If Customer does not object to the engagement of a third party in accordance with Section 4.2 within ten (10) days of notice by Mashgin, that third party will be deemed an Authorized Sub-Processor for the purposes of this DPA.</p><p>4.5 Mashgin will enter into a written agreement with the Authorized Sub-Processor imposing on the Authorized Sub-Processor data protection obligations comparable to those imposed on Mashgin under this DPA with respect to the protection of Personal Data. In case an Authorized Sub-Processor fails to fulfill its data protection obligations under such written agreement with Mashgin, Mashgin will remain liable to Customer for the performance of the Authorized Sub-Processor’s obligations under such agreement.</p><p>4.6 If Customer and Mashgin have entered into Standard Contractual Clauses as described in Section 6 (Transfers of Personal Data), (i) the above authorizations will constitute Customer’s prior written consent to the subcontracting by Mashgin of the processing of Personal Data if such consent is required under the Standard Contractual Clauses, and (ii) the parties agree that the copies of the agreements with Authorized Sub-Processors that must be provided by Mashgin to Customer pursuant to Clause 9(c) of the EU SCCs may have commercial information, or information unrelated to the Standard Contractual Clauses or their equivalent, removed by Mashgin beforehand, and that such copies will be provided by Mashgin only upon request by Customer.</p><h2><strong>5.</strong> <strong>Security of Personal Data. </strong></h2><p>Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, Mashgin shall maintain appropriate technical and organizational measures to ensure a level of security appropriate to the risk of processing Personal Data.<strong> </strong>Exhibit C sets forth additional information about Mashgin’s technical and organizational security measures.</p><p></p><h2><strong>6.</strong> <strong>Transfers of Personal Data</strong></h2><p>6.1 The parties agree that Mashgin may transfer Personal Data processed under this DPA outside the EEA, the UK, or Switzerland as necessary to provide the Services. Customer acknowledges that Mashgin’s primary processing operations take place in the United States, and that the transfer of Customer’s Personal Data to the United States is necessary for the provision of the Services to Customer. If Mashgin transfers Personal Data protected under this DPA to a jurisdiction for which the European Commission has not issued an adequacy decision, Mashgin will ensure that appropriate safeguards have been implemented for the transfer of Personal Data in accordance with Data Protection Laws.</p><p>6.2 Ex-EEA Transfers. The parties agree that ex-EEA Transfers are made pursuant to the EU SCCs, which are deemed entered into (and incorporated into this DPA by this reference) and completed as follows:</p><p>6.2.1 Module One (Controller to Controller) of the EU SCCs apply when Mashgin is processing Personal Data as a controller pursuant to Section 9 of this DPA. </p><p>6.2.2 Module Two (Controller to Processor) of the EU SCCs apply when Customer is a controller and Mashgin is processing Personal Data for Customer as a processor pursuant to Section 2 of this DPA.</p><p>6.2.3 Module Three (Processor to Sub-Processor) of the EU SCCs apply when Customer is a processor and Mashgin is processing Personal Data on behalf of Customer as a sub-processor.</p><p>6.3 For each module, where applicable the following applies:</p><p>6.3.1 The optional docking clause in Clause 7 does not apply;</p><p>6.3.2 In Clause 9, Option 2 (general written authorization) applies, and the minimum time period for prior notice of sub-processor changes shall be as set forth in Section 4.2 of this DPA;</p><p>6.3.3 In Clause 11, the optional language does not apply;</p><p>6.3.4 All square brackets in Clause 13 are hereby removed;</p><p>6.3.5 In Clause 17 (Option 1), the EU SCCs will be governed by Swedish law;</p><p>6.3.6 In Clause 18(b), disputes will be resolved before the courts of Stockholm, Sweden.</p><p>6.3.7 Exhibit B to this DPA contains the information required in Annex I and Annex III of the EU SCCs;</p><p>6.3.8 Exhibit C to this DPA contains the information required in Annex II of the EU SCCs; and</p><p>6.3.9 By entering into this DPA, the parties are deemed to have signed the EU SCCs incorporated herein, including their Annexes.</p><p>6.4 Ex-UK Transfers. The parties agree that ex-UK Transfers are made pursuant to the UK SCCs, which are deemed entered into and incorporated into this DPA by reference, and amended and completed in accordance with the UK Addendum, which is incorporated herein as Exhibit D of this DPA.</p><p>6.5 Transfers from Switzerland. The parties agree that transfers from Switzerland are made pursuant to the EU SCCs with the following modifications:</p><p>6.5.1 The terms “General Data Protection Regulation” or “Regulation (EU) 2016/679” as utilized in the EU SCCs shall be interpreted to include the Federal Act on Data Protection of 19 June 1992 (the “FADP,” and as revised as of 25 September 2020, the “Revised FADP”) with respect to data transfers subject to the FADP.</p><p>6.5.2 The terms of the EU SCCs shall be interpreted to protect the data of legal entities until the effective date of the Revised FADP.</p><p>6.5.3 Clause 13 of the EU SCCs is modified to provide that the Federal Data Protection and Information Commissioner (“FDPIC”) of Switzerland shall have authority over data transfers governed by the FADP and the appropriate EU supervisory authority shall have authority over data transfers governed by the GDPR. Subject to the foregoing, all other requirements of Section 13 shall be observed.</p><p>6.5.4 The term “EU Member State” as utilized in the EU SCCs shall not be interpreted in such a way as to exclude Data Subjects in Switzerland from exercising their rights in their place of habitual residence in accordance with Clause 18(c) of the EU SCCs.</p><p>6.6 Supplementary Measures. In respect of any ex-EEA Transfer or ex-UK Transfer, the following supplementary measures shall apply:</p><p>6.6.1 As of the date of this DPA, the Data Importer has not received any formal legal requests from any government intelligence or security service/agencies in the country to which the Personal Data is being exported, for access to (or for copies of) Customer’s Personal Data (“Government Agency Requests”)</p><p>6.6.2 If, after the date of this DPA, the Data Importer receives any Government Agency Requests, Mashgin shall attempt to redirect the law enforcement or government agency to request that data directly from the Customer. As part of this effort, Mashgin may provide Customer’s basic contact information to the government agency. If compelled to disclose Customer’s Personal Data to a law enforcement or government agency, Mashgin shall give Customer reasonable notice of the demand and cooperate to allow Customer to seek a protective order or other appropriate remedy unless Mashgin is legally prohibited from doing so. Mashgin shall not voluntarily disclose Personal Data to any law enforcement or government agency. Data Exporter and Data Importer shall (as soon as reasonably practicable) discuss and determine whether all or any transfers of Personal Data pursuant to this DPA should be suspended in the light of the such Government Agency Requests; and</p><p>6.6.3 The Data Exporter and Data Importer will meet regularly to consider whether:</p><p>(i) the protection afforded by the laws of the country of the Data Importer to data subjects whose Personal Data is being transferred is sufficient to provide broadly equivalent protection to that afforded in the EEA or the UK, whichever the case may be;</p><p>(ii) additional measures are reasonably necessary to enable the transfer to be compliant with the Data Protection Laws; and</p><p>(iii) it is still appropriate for Personal Data to be transferred to the relevant Data Importer, taking into account all relevant information available to the parties, together with guidance provided by the supervisory authorities.</p><p>6.6.4 If Data Protection Laws require the Data Exporter to execute the Standard Contractual Clauses applicable to a particular transfer of Personal Data to a Data Importer as a separate agreement, the Data Importer shall, on request of the Data Exporter, promptly execute such Standard Contractual Clauses incorporating such amendments as may reasonably be required by the Data Exporter to reflect the applicable appendices and annexes, the details of the transfer and the requirements of the relevant Data Protection Laws.</p><p>6.6.5 If either (i) any of the means of legitimizing transfers of Personal Data outside of the EEA or UK set forth in this DPA cease to be valid or (ii) any supervisory authority requires transfers of Personal Data pursuant to those means to be suspended, then Data Importer may by notice to the Data Exporter, with effect from the date set out in such notice, amend or put in place alternative arrangements in respect of such transfers, as required by Data Protection Laws.</p><h2><strong>7.</strong> <strong>Rights of Data Subjects</strong></h2><p>7.1 Mashgin shall, to the extent permitted by law, notify Customer upon receipt of a request by a Data Subject to exercise the Data Subject’s right of: access, rectification, erasure, data portability, restriction or cessation of processing, withdrawal of consent to processing, and/or objection to being subject to processing that constitutes automated decision-making (such requests individually and collectively “Data Subject Request(s)”). If Mashgin receives a Data Subject Request in relation to Customer’s data, Mashgin will advise the Data Subject to submit their request to Customer and Customer will be responsible for responding to such request, including, where necessary, by using the functionality of the Services. Customer is solely responsible for ensuring that Data Subject Requests for erasure, restriction or cessation of processing, or withdrawal of consent to processing of any Personal Data are communicated to Mashgin, and, if applicable, for ensuring that a record of consent to processing is maintained with respect to each Data Subject.</p><p>7.2 Mashgin shall, at the request of the Customer, and taking into account the nature of the processing applicable to any Data Subject Request, apply appropriate technical and organizational measures to assist Customer in complying with Customer’s obligation to respond to such Data Subject Request and/or in demonstrating such compliance, where possible, <em>provided that</em> (i) Customer is itself unable to respond without Mashgin’s assistance and (ii) Mashgin is able to do so in accordance with all applicable laws, rules, and regulations. Customer shall be responsible to the extent legally permitted for any costs and expenses arising from any such assistance by Mashgin.</p><h2><strong>8.</strong> <strong>Actions and Access Requests; Audits</strong></h2><p>8.1 Mashgin shall, taking into account the nature of the processing and the information available to Mashgin, provide Customer with reasonable cooperation and assistance where necessary for Customer to comply with its obligations under the GDPR to conduct a data protection impact assessment and/or to demonstrate such compliance, <em>provided that</em> Customer does not otherwise have access to the relevant information. Customer shall be responsible to the extent legally permitted for any costs and expenses arising from any such assistance by Mashgin.</p><p>8.2 Mashgin shall, taking into account the nature of the processing and the information available to Mashgin, provide Customer with reasonable cooperation and assistance with respect to Customer’s cooperation and/or prior consultation with any Supervisory Authority, where necessary and where required by the GDPR. Customer shall be responsible to the extent legally permitted for any costs and expenses arising from any such assistance by Mashgin.</p><p>8.3 Mashgin shall maintain records sufficient to demonstrate its compliance with its obligations under this DPA, and retain such records for a period of three (3) years after the termination of the Agreement. Customer shall, with reasonable notice to Mashgin, have the right to review, audit and copy such records at Mashgin’s offices during regular business hours.</p><p>8.4 Upon Customer’s written request at reasonable intervals, and subject to reasonable confidentiality controls, Mashgin shall, either (i) make available for Customer’s review copies of certifications or reports demonstrating Mashgin’s compliance with prevailing data security standards applicable to the processing of Customer’s Personal Data, or (ii) if the provision of reports or certifications pursuant to (i) is not reasonably sufficient under Data Protection Laws, allow Customer’s independent third party representative to conduct an audit or inspection of Mashgin’s data security infrastructure and procedures that is sufficient to demonstrate Mashgin’s compliance with its obligations under Data Protection Laws, provided that (a) Customer provides reasonable prior written notice of any such request for an audit and such inspection shall not be unreasonably disruptive to Mashgin’s business; (b) such audit shall only be performed during business hours and occur no more than once per calendar year; and (c) such audit shall be restricted to data relevant to Customer. Customer shall be responsible for the costs of any such audits or inspections, including without limitation a reimbursement to Mashgin for any time expended for on-site audits.<em> </em>If Customer and Mashgin have entered into Standard Contractual Clauses as described in Section 6 (Transfers of Personal Data), the parties agree that the audits described in Clause 8.9 of the EU SCCs shall be carried out in accordance with this Section 8.4.</p><p>8.5 Mashgin shall immediately notify Customer if an instruction, in Mashgin’s opinion, infringes the Data Protection Laws or Supervisory Authority.</p><p>8.6 In the event of a Personal Data Breach, Mashgin shall, without undue delay, inform Customer of the Personal Data Breach and take such steps as Mashgin in its sole discretion deems necessary and reasonable to remediate such violation (to the extent that remediation is within Mashgin’s reasonable control).</p><p>8.7 In the event of a Personal Data Breach, Mashgin shall, taking into account the nature of the processing and the information available to Mashgin, provide Customer with reasonable cooperation and assistance necessary for Customer to comply with its obligations under the GDPR with respect to notifying (i) the relevant Supervisory Authority and (ii) Data Subjects affected by such Personal Data Breach without undue delay.</p><p>8.8 The obligations described in Sections 8.6 and 8.7 shall not apply in the event that a Personal Data Breach results from the actions or omissions of Customer. Mashgin’s obligation to report or respond to a Personal Data Breach under Sections 8.6 and 8.7 will not be construed as an acknowledgement by Mashgin of any fault or liability with respect to the Personal Data Breach.</p><h2><strong>9.</strong> <strong>Mashgin’s Role as a Controller. </strong></h2><p><strong></strong>The parties acknowledge and agree that with respect to Mashgin Account Data and Mashgin Usage Data, Mashgin is an independent controller, not a joint controller with Customer. Mashgin will process Mashgin Account Data and Mashgin Usage Data as a controller (i) to manage the relationship with Customer; (ii) to carry out Mashgin’s core business operations, such as accounting, audits, tax preparation and filing and compliance purposes; (iii) to monitor, investigate, prevent and detect fraud, security incidents and other misuse of the Services, and to prevent harm to Customer; (iv) for identity verification purposes; (v) to comply with legal or regulatory obligations applicable to the processing and retention of Personal Data to which Mashgin is subject; and (vi) as otherwise permitted under Data Protection Laws and in accordance with this DPA and the Agreement. Mashgin may also process Mashgin Usage Data as a controller to provide, optimize, and maintain the Services, to the extent permitted by Data Protection Laws. Any processing by Mashgin as a controller shall be in accordance with Mashgin’s privacy policy set forth at<strong> </strong>https://www.mashgin.com/privacy-policy</p><h2><strong>10.</strong> <strong>Conflict. </strong></h2><p><strong></strong>In the event of any conflict or inconsistency among the following documents, the order of precedence will be: (1) the applicable terms in the Standard Contractual Clauses; (2) the terms of this DPA; (3) the Agreement; and (4) Mashgin’s privacy policy. Any claims brought in connection with this DPA will be subject to the terms and conditions, including, but not limited to, the exclusions and limitations set forth in the Agreement.</p><p></p><p><strong>Exhibit A</strong></p><h2><strong>Details of Processing</strong></h2><p><strong>Nature and Purpose of Processing:</strong> Mashgin will process Customer’s Personal Data as necessary to provide the Services under the Agreement, for the purposes specified in the Agreement and this DPA, and in accordance with Customer’s instructions as set forth in this DPA. The nature of processing includes, without limitation:</p><ul role="list"><li>Receiving data, including collection, accessing, retrieval, recording, and data entry</li><li>Holding data, including storage, organization and structuring</li><li>Using data, including analysis, consultation, testing, automated decision making and profiling</li><li>Updating data, including correcting, adaptation, alteration, alignment and combination</li><li>Protecting data, including restricting, encrypting, and security testing</li><li>Sharing data, including disclosure, dissemination, allowing access or otherwise making available</li><li>Returning data to the data exporter or data subject</li><li>Erasing data, including destruction and deletion</li></ul><p><strong> </strong></p><p><strong>Duration of Processing: </strong>Mashgin will process Customer’s Personal Data as long as required (i) to provide the Services to Customer under the Agreement; (ii) for Mashgin’s legitimate business needs; or (iii) by applicable law or regulation. Mashgin Account Data and Mashgin Usage Data will be processed and stored as set forth in Mashgin’s privacy policy.</p><p><strong> </strong></p><p><strong>Categories of Data Subjects: </strong>Customer end-users/customers AND/OR Customer employees</p><p><strong> </strong></p><p><strong>Categories of Personal Data: </strong>Mashgin processes Personal Data contained in Mashgin Account Data, Mashgin Usage Data, and any Personal Data provided by Customer (including any Personal Data Customer collects from its end users and processes through its use of the Services) or collected by Mashgin in order to provide the Services or as otherwise set forth in the Agreement or this DPA. Categories of Personal Data include those specified in Mashgin’s privacy policy.</p><p> </p><p><strong>Sensitive Data or Special Categories of Data: </strong>None</p><p></p><p><strong>Exhibit B</strong></p><p>The following includes the information required by Annex I and Annex III of the EU SCCs, and Table 1, Annex 1A, and Annex 1B of the UK Addendum.</p><h2><strong>1.</strong> <strong>The Parties</strong></h2><p><strong>Data exporter(s): </strong>The Customer</p><ul role="list"><li>Contact details: As designated by Customer in the contact detail section of the Order Form accompanying the Agreement.</li><li>Signature and date: By entering into the Agreement, Data Exporter is deemed to have signed these Standard Contractual Clauses incorporated herein, as of the Effective Date of the Agreement.</li><li>Role (controller/processor): The Data Exporter’s role is set forth in Section 2 of this Addendum.</li></ul><p> <strong>Data importer(s): </strong>Mashgin</p><p>Address: </p><p><em>849 East Charleston Road, Palo Alto, California 94303, United States</em></p><p>Contact person’s name, position and contact details: </p><p><em>Cody Dales, VP Compliance, email: cody@mashgin.com, tel: +1 (276) 312-9295</em></p><p>Signature and date: By entering into the Agreement, Data Importer is deemed to have signed these Standard Contractual Clauses incorporated herein, as of the Effective Date of the Agreement.</p><p>Role (controller/processor): The Data Importer’s role is set forth in Section 2 of this Addendum.</p><p> </p><h2><strong>2.</strong> <strong>Description of the Transfer</strong></h2><p> </p><div class="w-embed"><table style="width:100%; border-collapse:collapse;">
<tr>
<td style="border:1px solid #000; font-weight:bold; padding:6px;">Data Subjects</td>
<td style="border:1px solid #000; padding:6px;">As described in Exhibit A of the DPA</td>
</tr>
<tr>
<td style="border:1px solid #000; font-weight:bold; padding:6px;">Categories of Personal Data</td>
<td style="border:1px solid #000; padding:6px;">As described in Exhibit A of the DPA</td>
</tr>
<tr>
<td style="border:1px solid #000; font-weight:bold; padding:6px;">Special Category Personal Data (if applicable)</td>
<td style="border:1px solid #000; padding:6px;">As described in Exhibit A of the DPA</td>
</tr>
<tr>
<td style="border:1px solid #000; font-weight:bold; padding:6px;">Nature of the Processing</td>
<td style="border:1px solid #000; padding:6px;">As described in Exhibit A of the DPA</td>
</tr>
<tr>
<td style="border:1px solid #000; font-weight:bold; padding:6px;">Purposes of Processing</td>
<td style="border:1px solid #000; padding:6px;">As described in Exhibit A of the DPA</td>
</tr>
<tr>
<td style="border:1px solid #000; font-weight:bold; padding:6px;">Duration of Processing and Retention (or the criteria to determine such period)</td>
<td style="border:1px solid #000; padding:6px;">As described in Exhibit A of the DPA</td>
</tr>
<tr>
<td style="border:1px solid #000; font-weight:bold; padding:6px;">Frequency of the transfer</td>
<td style="border:1px solid #000; padding:6px;">As necessary to provide perform all obligations and rights with respect to Personal Data as provided in the Agreement</td>
</tr>
<tr>
<td style="border:1px solid #000; font-weight:bold; padding:6px;">Recipients of Personal Data Transferred to the Data Importer</td>
<td style="border:1px solid #000; padding:6px;">
Mashgin will maintain and provide a list of its Subprocessors upon request. Mashgin’s list of Subprocessors can be found in the following list “List of Authorized Sub-Processors.”
</td>
</tr>
</table></div><p></p><h2><strong>3.</strong> <strong>Competent Supervisory Authority</strong></h2><p> The supervisory authority shall be the supervisory authority of the Data Exporter, as determined in accordance with Clause 13 of the EU SCCs. The supervisory authority for the purposes of the UK Addendum shall be the UK Information Commissioner’s Officer.</p><p><strong> </strong></p><h2><strong>4.</strong> <strong>List of Authorized Sub-Processors</strong></h2><div class="w-embed"><style>
.responsive-table {
width: 100%;
border-collapse: collapse;
font-size: 14px;
}
.responsive-table th,
.responsive-table td {
border: 1px solid #000;
padding: 6px;
vertical-align: top;
}
.responsive-table th {
background: #f5f5f5;
text-align: left;
}
/* Mobile styles */
@media (max-width: 768px) {
.responsive-table,
.responsive-table thead,
.responsive-table tbody,
.responsive-table th,
.responsive-table td,
.responsive-table tr {
display: block;
width: 100%;
}
.responsive-table thead {
display: none;
}
.responsive-table tr {
border: 1px solid #000;
margin-bottom: 12px;
background: #fff;
}
/* cambio aquí: ya no dejamos hueco a la izquierda */
.responsive-table td {
border: none;
border-bottom: 1px solid #ddd;
padding: 8px 10px 8px 10px;
position: relative;
min-height: 0;
}
.responsive-table td:last-child {
border-bottom: none;
}
/* la etiqueta va ARRIBA, no al lado */
.responsive-table td::before {
content: attr(data-label);
display: block;
font-weight: bold;
margin-bottom: 4px;
position: static;
width: auto;
white-space: normal;
}
}
</style>
<table class="responsive-table">
<thead>
<tr>
<th>Name of Authorized Sub-Processor</th>
<th>Address</th>
<th>Contact Person Name, position, contact information</th>
<th>Description of processing</th>
<th>Country in which subprocessing will take place</th>
</tr>
</thead>
<tbody>
<tr>
<td data-label="Name of Authorized Sub-Processor">Amazon Web Services, Inc. “AWS”</td>
<td data-label="Address">410 Terry Avenue North, Seattle, WA 98109-5210, USA</td>
<td data-label="Contact Person Name, position, contact information">
Kyle Larrow<br>
klarrow@amazon.com<br>
508-944-3017<br>
https://aws.amazon.com/contact-us/compliance-support/
</td>
<td data-label="Description of processing">
Cloud hosting, storage, and computing services; database management; content delivery and other infrastructural services.
</td>
<td data-label="Country in which subprocessing will take place">USA</td>
</tr>
<tr>
<td data-label="Name of Authorized Sub-Processor">HubSpot, Inc.</td>
<td data-label="Address">25 First Street, 2nd Floor, Cambridge, MA 02141, USA</td>
<td data-label="Contact Person Name, position, contact information">privacy@hubspot.com</td>
<td data-label="Description of processing">
Customer relationship management, marketing automation, email marketing, analytics, and customer service data management.
</td>
<td data-label="Country in which subprocessing will take place">USA</td>
</tr>
<tr>
<td data-label="Name of Authorized Sub-Processor">Google, LLC</td>
<td data-label="Address">1600 Amphitheatre Parkway, Mountain View, CA 94043, USA</td>
<td data-label="Contact Person Name, position, contact information">
data-access-requests@google.com<br>
tel: 650.253.0000
</td>
<td data-label="Description of processing">
Email hosting, document storage and collaboration (Google Suite); website analytics, interactions, and data reporting (Google Analytics).
</td>
<td data-label="Country in which subprocessing will take place">USA</td>
</tr>
<tr>
<td data-label="Name of Authorized Sub-Processor">Slack Technologies, LLC</td>
<td data-label="Address">500 Howard Street, San Francisco, CA 94105, USA</td>
<td data-label="Contact Person Name, position, contact information">privacy@slack.com</td>
<td data-label="Description of processing">
Business communication platform providing messaging, file sharing, and collaboration tools.
</td>
<td data-label="Country in which subprocessing will take place">USA</td>
</tr>
<tr>
<td data-label="Name of Authorized Sub-Processor">Twilio, Inc.</td>
<td data-label="Address">375 Beale Street, Suite 300, San Francisco, CA 94105, USA</td>
<td data-label="Contact Person Name, position, contact information">privacy@twilio.com</td>
<td data-label="Description of processing">
Cloud communications platform offering messaging, voice, video, and email services.
</td>
<td data-label="Country in which subprocessing will take place">USA</td>
</tr>
<tr>
<td data-label="Name of Authorized Sub-Processor">Zoom Video Communications, Inc.</td>
<td data-label="Address">55 Almaden Boulevard, 6th Floor, San Jose, CA 95113, USA</td>
<td data-label="Contact Person Name, position, contact information">privacy@zoom.us</td>
<td data-label="Description of processing">
Video conferencing, web conferencing, and webinar hosting services.
</td>
<td data-label="Country in which subprocessing will take place">USA</td>
</tr>
<tr>
<td data-label="Name of Authorized Sub-Processor">Postmark (Wildbit, LLC)</td>
<td data-label="Address">225 Chestnut Street, Philadelphia, PA 19106, USA</td>
<td data-label="Contact Person Name, position, contact information">privacy@activecampaign.com</td>
<td data-label="Description of processing">
Email delivery service for transactional emails, including sending, receiving, and tracking emails.
</td>
<td data-label="Country in which subprocessing will take place">USA</td>
</tr>
<tr>
<td data-label="Name of Authorized Sub-Processor">FreedomPay, Inc.</td>
<td data-label="Address">10 N Independence Mall W, Philadelphia, PA 19106, USA</td>
<td data-label="Contact Person Name, position, contact information">compliance@freedompay.com</td>
<td data-label="Description of processing">
Payment processing services including transaction processing, data encryption, and financial data management.
</td>
<td data-label="Country in which subprocessing will take place">USA</td>
</tr>
<tr>
<td data-label="Name of Authorized Sub-Processor">Intuit, Inc.</td>
<td data-label="Address">2700 Coast Avenue, Mountain View, CA 94043, USA</td>
<td data-label="Contact Person Name, position, contact information">security@intuit.com</td>
<td data-label="Description of processing">
Financial and accounting software services, including tax preparation, payroll processing, and financial reporting.
</td>
<td data-label="Country in which subprocessing will take place">USA</td>
</tr>
<tr>
<td data-label="Name of Authorized Sub-Processor">Zendesk, Inc.</td>
<td data-label="Address">989 Market Street, San Francisco, CA 94103, USA</td>
<td data-label="Contact Person Name, position, contact information">privacy@zendesk.com</td>
<td data-label="Description of processing">
Customer service software and ticketing system providing support ticket tracking, customer support communications, and analytics.
</td>
<td data-label="Country in which subprocessing will take place">USA</td>
</tr>
<tr>
<td data-label="Name of Authorized Sub-Processor">Service Now, Inc.</td>
<td data-label="Address">2225 Lowsome Lane, Santa Clara, CA 95054, USA</td>
<td data-label="Contact Person Name, position, contact information">privacy@servicenow.com</td>
<td data-label="Description of processing">
Customer service software and ticketing system providing support ticket tracking, customer support communications, and analytics.
</td>
<td data-label="Country in which subprocessing will take place">USA</td>
</tr>
<tr>
<td data-label="Name of Authorized Sub-Processor">Five9, Inc.</td>
<td data-label="Address">3001 Bishop Drive, Suite 350, San Ramon, CA 94583, USA</td>
<td data-label="Contact Person Name, position, contact information">privacy@five9.com</td>
<td data-label="Description of processing">
Cloud communications platform offering messaging, voice, video, and email services.
</td>
<td data-label="Country in which subprocessing will take place">USA</td>
</tr>
<tr>
<td data-label="Name of Authorized Sub-Processor">Click-Up (Mango Technologies, Inc.)</td>
<td data-label="Address">5800 Armada Drive, Suite 300, Carlsbad, CA 92008, USA</td>
<td data-label="Contact Person Name, position, contact information">
John Hussey<br>
jhussey@clickup.com<br>
(781) 439-1293
</td>
<td data-label="Description of processing">
Project management tools offering task assignments, scheduling, document management, and collaboration features.
</td>
<td data-label="Country in which subprocessing will take place">USA</td>
</tr>
<tr>
<td data-label="Name of Authorized Sub-Processor">Smartsheet, Inc.</td>
<td data-label="Address">10500 NE 8th Street, Suite 1300, Bellevue, WA 98004, USA</td>
<td data-label="Contact Person Name, position, contact information">privacy@smartsheet.com</td>
<td data-label="Description of processing">
Work execution platform providing services for planning, tracking, automation, and reporting on work.
</td>
<td data-label="Country in which subprocessing will take place">USA</td>
</tr>
<tr>
<td data-label="Name of Authorized Sub-Processor">Height</td>
<td data-label="Address">222 Broadway, New York City, New York, 10038, USA</td>
<td data-label="Contact Person Name, position, contact information">team@height.app</td>
<td data-label="Description of processing">
Task management and collaboration software featuring task tracking, project management, and team collaboration tools.
</td>
<td data-label="Country in which subprocessing will take place">USA</td>
</tr>
<tr>
<td data-label="Name of Authorized Sub-Processor">Okta, Inc.</td>
<td data-label="Address">100 First Street, Suite 600, San Francisco, CA 94105, USA</td>
<td data-label="Contact Person Name, position, contact information">jake.mccarthy@okta.com</td>
<td data-label="Description of processing">
Identity management services including authentication, user management, and access control.
</td>
<td data-label="Country in which subprocessing will take place">USA</td>
</tr>
<tr>
<td data-label="Name of Authorized Sub-Processor">Cloudflare, Inc.</td>
<td data-label="Address">101 Townsend St, San Francisco, CA 94107, USA</td>
<td data-label="Contact Person Name, position, contact information">privacyquestions@cloudflare.com</td>
<td data-label="Description of processing">
Web infrastructure and security services such as DNS services, DDoS mitigation, and website performance optimization.
</td>
<td data-label="Country in which subprocessing will take place">USA</td>
</tr>
<tr>
<td data-label="Name of Authorized Sub-Processor">Rippling (Rippling PEO 1, Inc.)</td>
<td data-label="Address">55 Second St, Suite 1500, San Francisco, CA 94105, USA</td>
<td data-label="Contact Person Name, position, contact information">support@rippling.com</td>
<td data-label="Description of processing">
HR and IT management platform providing services such as payroll, benefits administration, employee onboarding, and device management.
</td>
<td data-label="Country in which subprocessing will take place">USA</td>
</tr>
<tr>
<td data-label="Name of Authorized Sub-Processor">Plane (Pilot Platform Inc.)</td>
<td data-label="Address">548 Market St. #91283, San Francisco, CA 94104, USA</td>
<td data-label="Contact Person Name, position, contact information">privacy@plane.com</td>
<td data-label="Description of processing">
Professional Employer Organization and employer of record for E.U.-based Mashgin staff. HR and payroll service.
</td>
<td data-label="Country in which subprocessing will take place">USA</td>
</tr>
<tr>
<td data-label="Name of Authorized Sub-Processor">GitLab, Inc.</td>
<td data-label="Address">268 Bush Street, #350, San Francisco, CA 94104, USA</td>
<td data-label="Contact Person Name, position, contact information">DPO@gitlab.com</td>
<td data-label="Description of processing">
Web-based DevOps lifecycle tool, offering code repository management.
</td>
<td data-label="Country in which subprocessing will take place">USA</td>
</tr>
<tr>
<td data-label="Name of Authorized Sub-Processor">Testiny (Mategra GmbH)</td>
<td data-label="Address">
Fasanstraße 25/14<br>
8052 Graz<br>
Austria
</td>
<td data-label="Contact Person Name, position, contact information">c.breitwieser@testiny.io</td>
<td data-label="Description of processing">
Software Quality Assurance “QA” testing automation software.
</td>
<td data-label="Country in which subprocessing will take place">Austria</td>
</tr>
<tr>
<td data-label="Name of Authorized Sub-Processor">Windcave</td>
<td data-label="Address">1601 N 7th St Suite 420, Phoenix, AZ 85006, USA</td>
<td data-label="Contact Person Name, position, contact information">support@windcave.com</td>
<td data-label="Description of processing">
Payment processing services including transaction processing, data encryption, and financial data management.
</td>
<td data-label="Country in which subprocessing will take place">USA</td>
</tr>
<tr>
<td data-label="Name of Authorized Sub-Processor">Shift4 (Shift4 Payments LLC)</td>
<td data-label="Address">3501 Corporate Pkwy, Center Valley, PA 18034, USA</td>
<td data-label="Contact Person Name, position, contact information">dpo@credorax.com</td>
<td data-label="Description of processing">
Payment processing services including transaction processing, data encryption, and financial data management.
</td>
<td data-label="Country in which subprocessing will take place">USA</td>
</tr>
</tbody>
</table></div><p></p><p><strong>Exhibit C</strong> </p><h2><strong>Description of the Technical and Organizational Security Measures implemented by the Data Importer</strong></h2><p>The following includes the information required by Annex II of the EU SCCs and Annex II of the UK Addendum.</p><div class="w-embed"><table style="width:100%; border-collapse:collapse; font-size:14px;">
<tr>
<th style="border:1px solid #000; padding:6px; background:#f5f5f5; text-align:left;">
Technical and Organizational Security Measure
</th>
<th style="border:1px solid #000; padding:6px; background:#f5f5f5; text-align:left;">
Details
</th>
</tr>
<tr>
<td style="border:1px solid #000; padding:6px;">Measures of pseudonymisation and encryption of personal data</td>
<td style="border:1px solid #000; padding:6px;">
At Rest: AES-256 / In Motion: ChaCha20 + TLS.<br><br>
For services performed within the EU, Mashgin receives less data from its partner payment processors, such as XEPS, which does not include the Name on Card field (i.e. no personal data requires pseudonymisation). Mashgin does not apply pseudonymisation to Mashgin Cloud data, e.g. user’s name and email.
</td>
</tr>
<tr>
<td style="border:1px solid #000; padding:6px;">Measures for ensuring ongoing confidentiality, integrity, availability and resilience of processing systems and services</td>
<td style="border:1px solid #000; padding:6px;">
Mashgin maintains a Business Continuity and Disaster Recovery Policy that is reviewed annually by the Mashgin Compliance Council. Mashgin’s Compliance Council organizes an annual table-top exercise for disaster recovery.<br><br>
Mashgin’s cloud services reside on Amazon Web Services. All internal data and APIs are contained within a private Virtual Private Cloud which is separate from the servers in our public VPC. All servers and kiosks are on an encrypted VPN over TLS that can only be accessed via a 2FA account with revocable privileges. Critical cloud servers are behind load balancers where capacity can be manually added on demand. Database and storage capacity also uses AWS so it can be scaled within and across availability zones on demand.<br><br>
Mashgin’s database is automatically backed up multiple times daily through Amazon Web Services (“AWS”), and such backups are stored for one month thereafter. Mashgin performs a quarterly back-up restoration test.
</td>
</tr>
<tr>
<td style="border:1px solid #000; padding:6px;">Measures for ensuring the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident</td>
<td style="border:1px solid #000; padding:6px;">
All reporting data, user data, and item/menu data is stored on AWS cloud servers and backed up at least once per day. Such data is securely transferred through the Cloud over secure protocols to Amazon Web Services.<br><br>
Physical security of service provider Amazon Web Services is the leading industry standard and documented publicly in the most recent SOC-II report for AWS. Mashgin currently defaults to AWS’s Boardman, Oregon data processing and storage facility.<br><br>
Mashgin’s database is automatically backed up multiple times daily through Amazon Web Services (“AWS”), and such backups are stored for one month thereafter.<br><br>
No sensitive information, including customer information, is permitted by Mashgin’s Information Security Policy to be stored locally. Rather, Mashgin’s Cloud architecture affords our clients’ data strong levels of encryption by means of its storage within industry-leading Amazon Web Services’ own data infrastructure and by means of TLS, SSH, and other relevant security protocols during transmission. All traffic is passed through our VPN which is ChaCha20 encrypted. Within this, all traffic is TLS encrypted.
</td>
</tr>
<tr>
<td style="border:1px solid #000; padding:6px;">Processes for regularly testing, assessing and evaluating the effectiveness of technical and organizational measures in order to ensure the security of the processing</td>
<td style="border:1px solid #000; padding:6px;">
Mashgin engages in once-yearly penetration testing by an accredited third party security firm.<br><br>
Mashgin conducts an annual information security policy review, an annual risk management exercise, an annual business continuity and disaster recovery exercise, and a patch management program.<br><br>
Mashgin utilizes the compliance automation and monitoring system Vanta to identify and act upon organizational weak spots to ensure appropriate implementation of required controls.
</td>
</tr>
<tr>
<td style="border:1px solid #000; padding:6px;">Measures for user identification and authorization</td>
<td style="border:1px solid #000; padding:6px;">
System administrators must sign-on and pass authentication via individual user accounts in order to gain access to administrative privileges to manage individual systems.<br><br>
Access controls to Mashgin production systems are limited to the fewest number of employees as is strictly required, and all access hereto must be secured behind two-factor authentication at minimum. Where technologically feasible and pertinent, access must also be secured behind the self-managed Mashgin VPN.<br><br>
All sensitive systems and applications must automatically enforce password strength requirements, history requirements, and reset requirements. For access to Google G-Suite accounts, strong password settings must be enabled across Company user accounts, and user account passwords must have a minimum length of ten characters, in compliance with the Strong Password Policy.
</td>
</tr>
<tr>
<td style="border:1px solid #000; padding:6px;">Measures for the protection of data during transmission</td>
<td style="border:1px solid #000; padding:6px;">
All traffic is passed through our VPN which is ChaCha20 encrypted. Within this, all traffic is TLS encrypted. Server data is encrypted via Amazon KMS.
</td>
</tr>
<tr>
<td style="border:1px solid #000; padding:6px;">Measures for the protection of data during storage</td>
<td style="border:1px solid #000; padding:6px;">
Data at rest is AES-256 encrypted.
</td>
</tr>
<tr>
<td style="border:1px solid #000; padding:6px;">Measures for ensuring physical security of locations at which personal data are processed</td>
<td style="border:1px solid #000; padding:6px;">
All reporting data, user data, and item/menu data is stored on AWS cloud servers and backed up at least once per day. Such data is securely transferred through the Cloud over secure protocols to Amazon Web Services.<br><br>
Physical security of service provider Amazon Web Services is the leading industry standard and documented publicly in the most recent SOC-II report for AWS. Mashgin currently defaults to AWS’s Boardman, Oregon data processing and storage facility.
</td>
</tr>
<tr>
<td style="border:1px solid #000; padding:6px;">Measures for ensuring events logging</td>
<td style="border:1px solid #000; padding:6px;">
Mashgin operates an in-house logging system for its systems and infrastructure. Staff access to all data is logged. All access to customer data is controlled via an account system.<br><br>
Changes and data updates are tracked via user and timestamp. Application logs are retained indefinitely. Our database is automatically backed up multiple times daily, with backups stored for one month. All AWS access is logged through AWS CloudTrail.
</td>
</tr>
<tr>
<td style="border:1px solid #000; padding:6px;">Measures for ensuring system configuration, including default configuration</td>
<td style="border:1px solid #000; padding:6px;">
N/A. Mashgin is a touchless checkout system and doesn't require a desktop workstation.
</td>
</tr>
<tr>
<td style="border:1px solid #000; padding:6px;">Measures for internal IT and IT security governance and management</td>
<td style="border:1px solid #000; padding:6px;">
Mashgin has established an internal council of department heads, the “Compliance Council”, to draft, review, and enforce various information security and operational policies and procedures.<br><br>
The Compliance Council maintains a library of compliance policies it frequently reviews. Mashgin has several recurring processes to disseminate information from the leadership team, keep the team apprised of cyber security news and updates, and to monitor and ensure good corporate governance.<br><br>
The Company is operated by a board of directors, conducts an annual ethical management survey, and utilizes advanced tools such as the Vanta automated compliance platform to monitor risk, security controls, and adherence to various security frameworks such as SOC 2.
</td>
</tr>
<tr>
<td style="border:1px solid #000; padding:6px;">Measures for certification/assurance of processes and products</td>
<td style="border:1px solid #000; padding:6px;">
Mashgin is SOC 2 Type 1 compliant.
</td>
</tr>
<tr>
<td style="border:1px solid #000; padding:6px;">Measures for ensuring data minimisation</td>
<td style="border:1px solid #000; padding:6px;">
Mashgin’s general policy is to process as little data as is required to render our services per contractual and legal obligations.
</td>
</tr>
<tr>
<td style="border:1px solid #000; padding:6px;">Measures for ensuring data quality</td>
<td style="border:1px solid #000; padding:6px;">
All client data is segregated logically. All data in our system is associated with a location. All locations belong to a unique client.<br><br>
All customer data will be associated with a client ID but otherwise stored in the same cloud database.
</td>
</tr>
<tr>
<td style="border:1px solid #000; padding:6px;">Measures for ensuring limited data retention</td>
<td style="border:1px solid #000; padding:6px;">
All data in our system is associated with a location. All locations belong to a unique client. All customer data will be associated with a client ID but otherwise stored in the same cloud database.<br><br>
Regarding physical access to Mashgin data, no personnel have access to the data storage facility maintained by Amazon Web Services. Regarding non-physical access, a fleshed-out policy and procedure exists within Mashgin’s InfoSec policy, and Mashgin seeks to provide only the minimum-required level of access and/or authority to personnel who may interact directly with sensitive data.<br><br>
Mashgin maintains the most stringent level of access control as is feasible in the scope of Company staff and resources. This includes the requirement of usage of a virtual private network with company-provided secure credentials to access such data. Customer data is retained for the life of the customer contract, available for export upon contract termination, and then deleted after contract ends upon request.
</td>
</tr>
<tr>
<td style="border:1px solid #000; padding:6px;">Measures for ensuring accountability</td>
<td style="border:1px solid #000; padding:6px;">
Mashgin’s Compliance Council conducts twice-annual information security awareness training for all staff. Mashgin’s Compliance department routinely shares cyber security and compliance updates to the channel #infosec on the Company’s internal Slack instant messenger service.<br><br>
Mashgin’s Compliance Council maintains a Compliance Library of various policies and procedures for information security and general operations, and requires all staff to sign and abide by the most current version of each policy.<br><br>
Mashgin’s Compliance team also shares examples of phishing attacks and more to increase the cyber security awareness of all staff.
</td>
</tr>
<tr>
<td style="border:1px solid #000; padding:6px;">Measures for allowing data portability and ensuring erasure</td>
<td style="border:1px solid #000; padding:6px;">
Mashgin maintains an Asset Management Policy that governs the data portability, removable devices, and data erasure.<br><br>
Mashgin also adheres to its Privacy Policy, publicly available on the web at <a href="https://www.mashgin.com/privacy-policy" target="_blank" rel="noopener noreferrer">https://www.mashgin.com/privacy-policy</a>.
</td>
</tr>
<tr>
<td style="border:1px solid #000; padding:6px;">Technical and organizational measures of sub-processors</td>
<td style="border:1px solid #000; padding:6px;">
Sub-processors such as Amazon Web Services (AWS), Google LLC (for Google Suite and Google Analytics), Slack Technologies, LLC, and others, implement a range of robust technical and organizational measures to protect the personal data they process. These measures are designed to provide a high level of security and data protection, irrespective of the nature of the data being processed or the service being provided.<br><br>
Common practices among these sub-processors include data encryption in transit and at rest, regular security assessments and penetration testing, and the deployment of firewalls and intrusion detection/prevention systems. These measures ensure the confidentiality, integrity, and availability of data, in line with GDPR’s Article 32 requirements.<br><br>
To comply with GDPR, sub-processors enforce strict access control and data management policies. Measures such as role-based access control (RBAC), two-factor authentication, and stringent employee vetting processes are commonplace. This ensures that only authorized personnel have access to personal data, and only for necessary purposes as stipulated by the processing agreement.<br><br>
Furthermore, sub-processors like Twilio Inc., Zoom Video Communications, Inc., and Intuit Inc. adopt data minimization principles, ensuring that only the necessary amount of data is processed and retained for the required duration. They also employ mechanisms for regular data backups, secure data deletion, and data recovery to safeguard against data loss or breaches.<br><br>
Sub-processors maintain a proactive stance towards regulatory compliance and are subject to regular audits, both internal and external, to assess their adherence to GDPR and other privacy standards. Companies such as Zendesk, Inc., ClickUp, and Cloudflare, Inc. not only comply with GDPR but often align with other international standards like ISO/IEC 27001, SOC 2, and others, further testifying to their commitment to data security.<br><br>
They engage in ongoing risk assessment and mitigation strategies, ensuring that their security postures evolve in response to new threats and changes in the regulatory landscape. Additionally, these sub-processors are transparent in their data processing activities, providing data subjects with rights such as access, rectification, erasure, and portability as mandated by the GDPR.
</td>
</tr>
</table></div><p></p><p><strong>Exhibit D</strong></p><h2><strong>UK Addendum</strong></h2><p><strong>International Data Transfer Addendum to the EU Commission Standard Contractual Clauses</strong></p><h3><strong>Part 1: Tables</strong></h3><div class="w-embed"><table style="width:100%; border-collapse:collapse; font-size:14px;">
<tr>
<td style="border:1px solid #000; padding:6px;">Start Date</td>
<td style="border:1px solid #000; padding:6px;" colspan="2">
This UK Addendum shall have the same effective date as the DPA
</td>
</tr>
<tr>
<td style="border:1px solid #000; padding:6px;">The Parties</td>
<td style="border:1px solid #000; padding:6px;">Exporter</td>
<td style="border:1px solid #000; padding:6px;">Importer</td>
</tr>
<tr>
<td style="border:1px solid #000; padding:6px;">Parties’ Details</td>
<td style="border:1px solid #000; padding:6px;">Customer</td>
<td style="border:1px solid #000; padding:6px;">Mashgin</td>
</tr>
<tr>
<td style="border:1px solid #000; padding:6px;">Key Contact</td>
<td style="border:1px solid #000; padding:6px;"><em>See Exhibit B of this DPA</em></td>
<td style="border:1px solid #000; padding:6px;"><em>See Exhibit B of this DPA</em></td>
</tr>
</table></div><p></p><h3>Table 2: Selected SCCs, Modules and Selected Clauses</h3><div class="w-embed"><table style="width:100%; border-collapse:collapse; font-size:14px;">
<tr>
<td style="border:1px solid #000; padding:6px; width:20%;">EU SCCs</td>
<td style="border:1px solid #000; padding:6px;">
The Version of the Approved EU SCCs which this UK Addendum is appended to as defined in the DPA and completed by Section 6.2 and 6.3 of the DPA.
</td>
</tr>
</table></div><p> </p><h3>Table 3: Appendix Information</h3><p>“Appendix Information” means the information which must be provided for the selected modules as set out in the Appendix of the Approved EU SCCs (other than the Parties), and which for this UK Addendum is set out in:</p><div class="w-embed"><table style="width:100%; border-collapse:collapse; font-size:14px;">
<tr>
<td style="border:1px solid #000; padding:6px;">Annex 1A: List of Parties</td>
<td style="border:1px solid #000; padding:6px;">As per Table 1 above</td>
</tr>
<tr>
<td style="border:1px solid #000; padding:6px;">Annex 2B: Description of Transfer</td>
<td style="border:1px solid #000; padding:6px;"><em>See Exhibit B of this DPA</em></td>
</tr>
<tr>
<td style="border:1px solid #000; padding:6px;">
Annex II: Technical and organizational measures including technical and organizational measures to ensure the security of the data:
</td>
<td style="border:1px solid #000; padding:6px;"><em>See Exhibit C of this DPA</em></td>
</tr>
<tr>
<td style="border:1px solid #000; padding:6px;">
Annex III: List of Sub processors (Modules 2 and 3 only):
</td>
<td style="border:1px solid #000; padding:6px;"><em>See Exhibit B of this DPA</em></td>
</tr>
</table></div><p><strong> </strong></p><h3><strong>Table 4: Ending this UK Addendum when the Approved UK Addendum Changes</strong></h3><div class="w-embed"><table style="width:100%; border-collapse:collapse; font-size:14px;">
<tr>
<td style="border:1px solid #000; padding:6px; width:50%;">
Ending this UK Addendum when the Approved UK Addendum changes
</td>
<td style="border:1px solid #000; padding:6px; width:50%;">
☒ <u>Importer</u><br>
☐ <u>Exporter</u><br>
☐ <u>Neither Party</u>
</td>
</tr>
</table></div><h3> </h3><h3><strong>Entering into this UK Addendum:</strong></h3><p>1. Each party agrees to be bound by the terms and conditions set out in this UK Addendum, in exchange for the other party also agreeing to be bound by this UK Addendum.</p><p>2. Although Annex 1A and Clause 7 of the Approved EU SCCs require signature by the Parties, for the purpose of making ex-UK Transfers, the Parties may enter into this UK Addendum in any way that makes them legally binding on the Parties and allows data subjects to enforce their rights as set out in this UK Addendum. Entering into this UK Addendum will have the same effect as signing the Approved EU SCCs and any part of the Approved EU SCCs.</p><h3><strong>Interpretation of this UK Addendum</strong></h3><p>3. Where this UK Addendum uses terms that are defined in the Approved EU SCCs those terms shall have the same meaning as in the Approved EU SCCs. In addition, the following terms have the following meanings:</p><div class="w-embed"><table style="width:100%; border-collapse:collapse; font-size:14px;">
<tr>
<td style="border:1px solid #000; padding:6px;">UK Addendum</td>
<td style="border:1px solid #000; padding:6px;">
means this International Data Transfer Addendum incorporating the EU SCCs, attached to the DPA as Exhibit D.
</td>
</tr>
<tr>
<td style="border:1px solid #000; padding:6px;">EU SCCs</td>
<td style="border:1px solid #000; padding:6px;">
means the version(s) of the Approved EU SCCs which this UK Addendum is appended to, as set out in Table 2, including the Appendix Information.
</td>
</tr>
<tr>
<td style="border:1px solid #000; padding:6px;">Appendix Information</td>
<td style="border:1px solid #000; padding:6px;">
shall be as set out in Table 3.
</td>
</tr>
<tr>
<td style="border:1px solid #000; padding:6px;">Appropriate Safeguards</td>
<td style="border:1px solid #000; padding:6px;">
means the standard of protection over the personal data and of data subjects’ rights, which is required by UK Data Protection Laws when you are making an ex-UK Transfer relying on standard data protection clauses under Article 46(2)(d) UK GDPR.
</td>
</tr>
<tr>
<td style="border:1px solid #000; padding:6px;">Approved UK Addendum</td>
<td style="border:1px solid #000; padding:6px;">
means the template Addendum issued by the ICO and laid before Parliament in accordance with s119A of the Data Protection Act 2018 on 2 February 2022, as may be revised under Section 19 of the UK Addendum.
</td>
</tr>
<tr>
<td style="border:1px solid #000; padding:6px;">Approved EU SCCs</td>
<td style="border:1px solid #000; padding:6px;">
means the standard contractual clauses approved by the European Commission in Commission Decision 2021/914 dated 4 June 2021, for transfers of personal data to countries not otherwise recognized as offering an adequate level of protection for personal data by the European Commission (as amended and updated from time to time).
</td>
</tr>
<tr>
<td style="border:1px solid #000; padding:6px;">ICO</td>
<td style="border:1px solid #000; padding:6px;">
means the Information Commissioner of the United Kingdom.
</td>
</tr>
<tr>
<td style="border:1px solid #000; padding:6px;">ex-UK Transfer</td>
<td style="border:1px solid #000; padding:6px;">
shall have the same definition as set forth in the DPA.
</td>
</tr>
<tr>
<td style="border:1px solid #000; padding:6px;">UK</td>
<td style="border:1px solid #000; padding:6px;">
means the United Kingdom of Great Britain and Northern Ireland.
</td>
</tr>
<tr>
<td style="border:1px solid #000; padding:6px;">UK Data Protection Laws</td>
<td style="border:1px solid #000; padding:6px;">
means all laws relating to data protection, the processing of personal data, privacy and/or electronic communications in force from time to time in the UK, including the UK GDPR and the Data Protection Act 2018.
</td>
</tr>
<tr>
<td style="border:1px solid #000; padding:6px;">UK GDPR</td>
<td style="border:1px solid #000; padding:6px;">
shall have the definition set forth in the DPA.
</td>
</tr>
</table></div><p>4. The UK Addendum must always be interpreted in a manner that is consistent with UK Data Protection Laws and so that it fulfills the Parties’ obligation to provide the Appropriate Safeguards.</p><p>5. If the provisions included in the UK Addendum amend the Approved EU SCCs in any way which is not permitted under the Approved EU SCCs or the Approved UK Addendum, such amendment(s) will not be incorporated in the UK Addendum and the equivalent provision of the Approved EU SCCs will take their place.</p><p>6. If there is any inconsistency or conflict between UK Data Protection Laws and the UK Addendum, UK Data Protection Laws apply.</p><p>7. If the meaning of the UK Addendum is unclear or there is more than one meaning, the meaning which most closely aligns with UK Data Protection Laws applies.</p><p>8. Any references to legislation (or specific provisions of legislation) means that legislation (or specific provision) as it may change over time. This includes where that legislation (or specific provision) has been consolidated, re-enacted and/or replaced after the UK Addendum has been entered into.</p><p> </p><h3><strong>Hierarchy</strong></h3><p>9. Although Clause 5 of the Approved EU SCCs sets out that the Approved EU SCCs prevail over all related agreements between the parties, the parties agree that, for ex-UK Transfers, the hierarchy in Section 10 below will prevail.</p><p>10. Where there is any inconsistency or conflict between the Approved UK Addendum and the EU SCCs (as applicable), the Approved UK Addendum overrides the EU SCCs, except where (and in so far as) the inconsistent or conflicting terms of the EU SCCs provides greater protection for data subjects, in which case those terms will override the Approved UK Addendum.</p><p>11. Where this UK Addendum incorporates EU SCCs which have been entered into to protect ex-EU Transfers subject to the GDPR, then the parties acknowledge that nothing in the UK Addendum impacts those EU SCCs.</p><h3><strong>Incorporation and Changes to the EU SCCs:</strong></h3><p>12. This UK Addendum incorporates the EU SCCs which are amended to the extent necessary so that:</p><p>a) together they operate for data transfers made by the data exporter to the data importer, to the extent that UK Data Protection Laws apply to the data exporter’s processing when making that data transfer, and they provide Appropriate Safeguards for those data transfers;</p><p>b) Sections 9 to 11 above override Clause 5 (Hierarchy) of the EU SCCs; and</p><p>13. the UK Addendum (including the EU SCCs incorporated into it) is (1) governed by the laws of England and Wales and (2) any dispute arising from it is resolved by the courts of England and Wales.</p><p>14. Unless the parties have agreed alternative amendments which meet the requirements of Section 12 of this UK Addendum, the provisions of Section 15 of this UK Addendum will apply.</p><p>15. No amendments to the Approved EU SCCs other than to meet the requirements of Section 12 of this UK Addendum may be made.</p><p>16. The following amendments to the EU SCCs (for the purpose of Section 12 of this UK Addendum) are made:</p><p>a) References to the “Clauses” means this UK Addendum, incorporating the EU SCCs;</p><p>b) In Clause 2, delete the words: “and, with respect to data transfers from controllers to processors and/or processors to processors, standard contractual clauses pursuant to Article 28(7) of Regulation (EU) 2016/679”,</p><p>c) Clause 6 (Description of the transfer(s)) is replaced with: “The details of the transfers(s) and in particular the categories of personal data that are transferred and the purpose(s) for which they are transferred) are those specified in Annex I.B where UK Data Protection Laws apply to the data exporter’s processing when making that transfer.”;</p><p>d) Clause 8.7(i) of Module 1 is replaced with: “it is to a country benefiting from adequacy regulations pursuant to Section 17A of the UK GDPR that covers the onward transfer”;</p><p>e) Clause 8.8(i) of Modules 2 and 3 is replaced with: “the onward transfer is to a country benefiting from adequacy regulations pursuant to Section 17A of the UK GDPR that covers the onward transfer;”</p><p>f) References to “Regulation (EU) 2016/679”, “Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation)” and “that Regulation” are all replaced by “UK Data Protection Laws”. References to specific Article(s) of “Regulation (EU) 2016/679” are replaced with the equivalent Article or Section of UK Data Protection Laws;</p><p>g) References to Regulation (EU) 2018/1725 are removed;</p><p>h) References to the “European Union”, “Union”, “EU”, “EU Member State”, “Member State” and “EU or Member State” are all replaced with the “UK”;</p><p>i) The reference to “Clause 12(c)(i)” at Clause 10(b)(i) of Module one, is replaced with “Clause 11(c)(i)”;</p><p>j) Clause 13(a) and Part C of Annex I are not used;</p><p>k) The “competent supervisory authority” and “supervisory authority” are both replaced with the “Information Commissioner”;</p><p>l) In Clause 16(e), subsection (i) is replaced with: “the Secretary of State makes regulations pursuant to Section 17A of the Data Protection Act 2018 that cover the transfer of personal data to which these clauses apply;”;</p><p>m) Clause 17 is replaced with: “These Clauses are governed by the laws of England and Wales;</p><p>n) Clause 18 is replaced with: “Any dispute arising from these Clauses shall be resolved by the courts of England and Wales. A data subject may also bring legal proceedings against the data exporter and/or data importer before the courts of any country in the UK. The parties agree to submit themselves to the jurisdiction of such courts.”; and</p><p>o) The footnotes to the Approved EU SCCs do not form part of the UK Addendum, except for footnotes 8, 9, 10 and 11.</p><p></p><h3><strong>Amendments to the UK Addendum</strong></h3><p>17. The parties may agree to change Clauses 17 and/or 18 of the EU SCCs to refer to the laws and/or courts of Scotland and Northern Ireland.</p><p>18. If the parties wish to change the format of the information included in Part 1: Tables of the Approved UK Addendum, they may do so by agreeing to the change in writing, provided that the change does not reduce the Appropriate Safeguards.</p><p>19. From time to time, the ICO may issue a revised Approved UK Addendum which:</p><p>a) makes reasonable and proportionate changes to the Approved UK Addendum, including correcting errors in the Approved UK Addendum; and/or</p><p>b) reflects changes to UK Data Protection Laws;</p><p>The revised Approved UK Addendum will specify the start date from which the changes to the Approved UK Addendum are effective and whether the parties need to review this UK Addendum including the Appendix Information. This UK Addendum is automatically amended as set out in the revised Approved UK Addendum from the start date specified.</p><p>20. If the ICO issues a revised Approved UK Addendum under Section 18 of this UK Addendum, if a party will as a direct result of the changes in the Approved UK Addendum have a substantial, disproportionate and demonstrable increase in:</p><p>c) its direct costs of performing its obligations under the UK Addendum; and/or</p><p>d) its risk under the UK Addendum,</p><p>and in either case it has first taken reasonable steps to reduce those costs or risks so that it is not substantial and disproportionate, then that party may end this UK Addendum at the end of a reasonable notice period, by providing written notice for that period to the other party before the start date of the revised Approved UK Addendum.</p><p>21. The parties do not need the consent of any third party to make changes to this UK Addendum, but any changes must be made in accordance with its terms</p><p></p><p><strong>Exhibit E</strong></p><h2><strong>United States Privacy Law Exhibit </strong></h2><p>This United States Privacy Law Exhibit (“Exhibit”) supplements the DPA and includes additional information required by the CCPA, the VCDPA, the CPA, the CTDPA, the UCPA, and the MHMDA in each case, as updated, amended or replaced from time to time. Any terms not defined in this Exhibit shall have the meanings set forth in the DPA and/or the Agreement. </p><h3><strong>A. CALIFORNIA</strong></h3><h4>1. Definitions <br/></h4><ol role="list"><li>For purposes of this Section A, the terms “Business,” “Business Purpose,” “Commercial Purpose,” “Consumer,” “Personal Information,” “Processing,” “Sell,” “Service Provider,” “Share,” and “Verifiable Consumer Request” shall have the meanings set forth in the CCPA.</li><li>All references to “Personal Data,” “Controller,” “Processor,” and “Data Subject” in the DPA shall be deemed to be references to “Personal Information,” “Business,” “Service Provider,” and “Consumer,” respectively, as defined in the CCPA.</li></ol><h4>2. Obligations <br/></h4><ol role="list"><li>Except with respect to Mashgin Account Data and Mashgin Usage Data (as defined in the DPA), the parties acknowledge and agree that Mashgin is a Service Provider for the purposes of the CCPA (to the extent it applies) and Mashgin is receiving Personal Information from Customer in order to provide the Services pursuant to the Agreement, which constitutes a Business Purpose.</li><li>Customer shall disclose Personal Information to Mashgin only for the limited and specified purposes described in Exhibit A to this DPA.</li><li>Mashgin shall not Sell or Share Personal Information provided by Customer under the Agreement.</li><li>Mashgin shall not retain, use, or disclose Personal Information provided by Customer pursuant to the Agreement for any purpose, including a Commercial Purpose, other than as necessary for the specific purpose of performing the Services for Customer pursuant to the Agreement, or as otherwise set forth in the Agreement or as permitted by the CCPA. </li><li>Mashgin shall not retain, use, or disclose Personal Information provided by Customer pursuant to the Agreement outside of the direct business relationship between Mashgin and Customer, except where and to the extent permitted by the CCPA. </li><li>Mashgin shall notify Customer if it makes a determination that it can no longer meet its obligations under the CCPA.</li><li>Mashgin will not combine Personal Information received from, or on behalf of, Customer with Personal Information that it receives from, or on behalf of, another party, or that it collects from its own interaction with the Consumer.</li><li>Mashgin shall comply with all obligations applicable to Service Providers under the CCPA, including by providing Personal Information provided by Customer under the Agreement the level of privacy protection required by CCPA.</li><li> Mashgin shall only engage a new subprocessor to assist Mashgin in providing the Services to Customer under the Agreement in accordance with Section 4.1 of the DPA, including, without limitation, by: (i) notifying Customer of such engagement via the notification mechanism described in Section 4.1 of the DPA at least ten (10) days before enabling a new Subprocessor; and (ii) entering into a written contract with the subprocessor requiring subprocessor to observe all of the applicable requirements set forth in the CCPA.</li></ol><h4>3. Consumer Rights <br/></h4><ol role="list"><li>Mashgin shall assist Customer in responding to Verifiable Consumer Requests to exercise the Consumer’s rights under the CCPA as set forth in Section 7 of the DPA.</li></ol><h4>4. Audit and Remediation Rights <br/></h4><ol role="list"><li>To the extent required by CCPA, Mashgin shall allow Customer to conduct inspections or audits in accordance with Sections 8.3 and 8.4 of the DPA.</li><li>If Customer determines that Mashgin is Processing Personal Information in an unauthorized manner, Customer may, taking into account the nature of the Mashgin’s Processing and the nature of the Personal Information Processed by Mashgin on behalf of Customer, take commercially reasonable and appropriate steps to stop and remediate such unauthorized Processing. </li></ol><h3><strong>B. VIRGINIA</strong></h3><h4>1. Definitions</h4><ol role="list"><li>For purposes of this Section B, the terms “Consumer,” “Controller,” “Personal Data,” “Processing,” and “Processor” shall have the meanings set forth in the VCDPA. </li><li>All references to “Data Subject” in this DPA shall be deemed to be references to “Consumer” as defined in the VCDPA.</li></ol><h4>2. Obligations</h4><ol role="list"><li>Except with respect to Mashgin Account Data and Mashgin Usage Data (as defined in the DPA), the parties acknowledge and agree that Customer is a Controller and Mashgin is a Processor for the purposes of the VCDPA (to extent it applies).</li><li>The nature, purpose, and duration of Processing, as well as the types of Personal Data and categories of Consumers are described in Exhibit A to this DPA.</li><li>Mashgin shall adhere to Customer’s instructions with respect to the Processing of Customer Personal Data and shall assist Customer in meeting its obligations under the VCDPA by: <br/><ol role="list"><li>Assisting Customer in responding to Consumer rights requests under the VCDPA as set forth in Section 7 of the DPA;</li><li>Complying with Section 5 (“Security of Personal Data”) of the DPA with respect to Personal Data provided by Customer;</li><li>In the event of a Personal Data Breach, providing information sufficient to enable Customer to meet its obligations pursuant to Virginia’s breach notification laws (Va. Code § 18.2-186.6); and</li><li>Providing information sufficient to enable Customer to conduct and document data protection assessments to the extent required by VCDPA.</li></ol></li><li>Mashgin shall maintain the confidentiality of Personal Data provided by Customer and require that each person Processing such Personal Data be subject to a duty of confidentiality with respect to such Processing.</li><li>Upon Customer’s written request, Mashgin shall delete or return all Personal Data provided by Customer in accordance with Section 2.4 of the DPA, unless retention of such Personal Data is required or authorized by law or the DPA and/or Agreement.</li><li>In the event that Mashgin engages a new subprocessor to assist Mashgin in providing the Services to Customer under the Agreement, Mashgin shall enter into a written contract with the subprocessor requiring subprocessor to observe all of the applicable requirements of a Processor set forth in the VCDPA.</li></ol><h4>3. Audit Rights</h4><ol role="list"><li>Upon Customer’s written request at reasonable intervals, Mashgin shall, as set forth in Sections 8.3-8.4 of the DPA, (i) make available to Customer all information in its possession that is reasonably necessary to demonstrate Mashgin’s compliance with its obligations under the VCDPA and (ii) allow and cooperate with reasonable inspections or audits as required under the VCDPA. </li></ol><h3><strong>C. COLORADO</strong></h3><h4>1. Definitions</h4><ol role="list"><li>For purposes of this Section C, the terms “Consumer,” “Controller,” “Personal Data,” “Processing,” and “Processor” shall have the meanings set forth in the CPA.</li><li>All references to “Data Subject” in the DPA shall be deemed to be references to “Consumer” as defined in the CPA.</li></ol><h4>2. Obligations</h4><ol role="list"><li>Except with respect to Mashgin Account Data and Mashgin Usage Data (as defined in the DPA), the parties acknowledge and agree that Customer is a Controller and Mashgin is a Processor for the purposes of the CPA (to extent it applies).</li><li>The nature, purpose, and duration of Processing, as well as the types of Personal Data and categories of Consumers are described in Exhibit A to this DPA.</li><li>Mashgin shall require that each person Processing such Personal Data be subject to a duty of confidentiality with respect to such Processing.</li><li>Mashgin shall only engage a new subcontractor to assist Mashgin in providing the Services to Customer under the Agreement in accordance with Section 4.1 of the DPA, including, without limitation, by: (i) notifying Customer of such engagement via the notification mechanism described in Section 4.1 of the DPA and providing Customer with an opportunity to object and (ii) entering into a written contract with the subcontractor requiring subcontractor to observe all of the applicable requirements set forth in the CPA.</li><li>Mashgin shall be responsible for taking the appropriate technical and organizational measures as described in Exhibit C. Customer shall be responsible for implementing appropriate technical and organizational measures to ensure a level of security appropriate to the risk.</li><li>Upon Customer’s written request, Mashgin shall delete or return all Personal Data provided by Customer in accordance with Section 2.4 of the DPA, unless retention of such Personal Data is required or authorized by law or the DPA and/or Agreement.</li></ol><h4>3. Audit Rights</h4><ol role="list"><li>Upon Customer’s written request at reasonable intervals, Mashgin shall, as set forth in Sections 8.3-8.4 of the DPA, (i) make available to Customer all information in its possession that is reasonably necessary to demonstrate Mashgin’s compliance with its obligations under the CPA and (ii) allow and cooperate with reasonable inspections or audits as required or permitted under the CPA.</li></ol><h3><strong>D. CONNECTICUT</strong></h3><h4>1. Definitions</h4><ol role="list"><li>For purposes of this Section D, the terms “Consumer,” “Controller,” “Personal Data,” “Processing,” and “Processor” shall have the meanings set forth in the CTDPA.</li><li>All references to “Data Subject” in the DPA shall be deemed to be references to “Consumer” as defined in the CTDPA.</li></ol><h4>2. Obligations</h4><ol role="list"><li>Except with respect to Mashgin Account Data and Mashgin Usage Data (as defined in the DPA), the parties acknowledge and agree that Customer is a Controller and Mashgin is a Processor for the purposes of the CTDPA (to extent it applies).</li><li>The nature, purpose, and duration of Processing, as well as the types of Personal Data and categories of Consumers are described in Exhibit A to this DPA.</li><li>Mashgin shall require that each person Processing such Personal Data be subject to a duty of confidentiality with respect to such Processing.</li><li>Mashgin shall only engage a new subcontractor to assist Mashgin in providing the Services to Customer under the Agreement in accordance with Section 4.1 of the DPA, including, without limitation, by: (i) notifying Customer of such engagement via the notification mechanism described in Section 4.1 of the DPA and providing Customer with an opportunity to object and (ii) entering into a written contract with the subcontractor requiring subcontractor to observe all of the applicable requirements set forth in the CTDPA.</li><li>Upon Customer’s written request, Mashgin shall delete or return all Personal Data provided by Customer in accordance with Section 2.4 of the DPA, unless retention of such Personal Data is required or authorized by law or the DPA and/or Agreement.</li></ol><h4>3. Audit Rights</h4><ol role="list"><li>Upon Customer’s written request at reasonable intervals, Mashgin shall, as set forth in Sections 8.3-8.4 of the DPA, (i) make available to Customer all information in its possession that is reasonably necessary to demonstrate Mashgin’s compliance with its obligations under the CTDPA and (ii) allow and cooperate with reasonable inspections or audits as required under the CTDPA.</li></ol><h3><strong>E. UTAH</strong></h3><h4>1. Definitions</h4><ol role="list"><li>For purposes of this Section E, the terms “Consumer,” “Controller,” “Personal Data,” “Processing,” and “Processor” shall have the meanings set forth in the UCPA.</li><li>All references to “Data Subject” in the DPA shall be deemed to be references to “Consumer” as defined in the UCPA.</li></ol><h4>2. Obligations</h4><ol role="list"><li>Except with respect to Mashgin Account Data and Mashgin Usage Data (as defined in the DPA), the parties acknowledge and agree that Customer is a Controller and Mashgin is a Processor for the purposes of the UCPA (to extent it applies).</li><li>The instructions with respect to the Processing of Customer Personal Data and the parties’ rights and obligations are set forth in this DPA and the Agreement.</li><li>The nature, purpose, and duration of Processing, as well as the types of Personal Data and categories of Consumers are described in Exhibit A to this DPA.</li><li>Mashgin shall require that each person Processing such Personal Data be subject to a duty of confidentiality with respect to such Processing.</li><li>Mashgin shall only engage a new subcontractor to assist Mashgin in providing the Services to Customer under the Agreement in accordance with Section 4.1 of the DPA, including, without limitation, by entering into a written contract with the subcontractor requiring subcontractor to observe all of the applicable requirements set forth in the UCPA.</li></ol><h3><strong>F. WASHINGTON</strong></h3><h4>1. Definitions</h4><ol role="list"><li>For purposes of this Section F, the terms “Consumer Health Data,” “Processor,” “Regulated Entity,” “Small Business,” and “Process” or “Processing” shall have the meanings set forth in the MHMDA. </li><li>All references to “Data Subject” in the DPA shall be deemed to be references to “Consumer” as defined in the MHMDA.</li></ol><h4>2. Obligations</h4><ol role="list"><li>Except with respect to Mashgin Account Data and Mashgin Usage Data (as defined in the DPA), the parties acknowledge and agree that Mashgin is a Processor for the purposes of the MHMDA (to the extent it applies). </li><li>The Customer’s instructions with respect to the Mashgin’s Processing of Consumer Health Data and each party’s respective rights and obligations are set forth in this DPA and the Agreement.</li><li>The nature, purpose, and duration of Processing, as well as the types of Consumer Health Data and categories of Consumers are described in Exhibit A to this DPA.</li><li>Mashgin shall be responsible for taking the appropriate technical and organizational measures as described in Exhibit C. Customer shall be responsible for implementing appropriate technical and organizational measures to ensure a level of security appropriate to the risk. </li><li>Mashgin acknowledges that if it fails to adhere to Customer’s instructions or processes Consumer Health Data outside of the scope of the Agreement or this DPA, Mashgin may be subject to all the obligations as a Regulated Entity or a Small Business, as applicable, pursuant to the MHMDA.</li></ol></div></div></div></section><section class="c-section cc-bg_black-400"><div class="c-container cc-footer"><div id="w-node-_7a304a7d-8d29-13df-18d2-1581bf71433f-bf71433d" class="c-wrap"><img src="https://cdn.prod.website-files.com/603557fca6b5097977fbac59/68ba93408a431b3050ec1e87_Logo.png" loading="lazy" alt="" class="c-footer_logo"/><p class="c-footer_paragraph">Mashgin is a registered trademark of Mashgin Inc.<br/>© 2026 Mashgin Inc.</p><p class="c-footer_paragraph"><a href="/privacy-policy" class="cc-text_orange">Privacy</a>, <a href="/terms-and-conditions" class="cc-text_orange">Terms</a>, <a href="/data-processing-addendum" aria-current="page" class="cc-text_orange w--current">Data Processing Addendum </a>& <a href="https://app.vanta.com/mashgin/trust/kcf7v3c0lmi6x6fkbg7c23" target="_blank" class="cc-text_orange">Data Security</a></p></div><div id="w-node-_7a304a7d-8d29-13df-18d2-1581bf71434e-bf71433d" class="c-wrap cc-gap_2"><div class="c-footer_heading">Solution</div><a href="/solution/overview" class="c-footer_link">Platform Overview</a><a href="/solution/integrations" class="c-footer_link">Integrations</a><a href="/solution/mashgin-photos" class="c-footer_link">Photo Gallery</a><a href="/solution/video-gallery" class="c-footer_link">Video Gallery</a></div><div id="w-node-_7a304a7d-8d29-13df-18d2-1581bf714357-bf71433d" class="c-wrap cc-gap_2"><div class="c-footer_heading">Industries</div><a href="/industry/convenience-stores" class="c-footer_link">Convenience</a><a href="/industry/sports-entertainment-venues" class="c-footer_link">Stadiums</a><a href="/industry/higher-education" class="c-footer_link">Higher Ed</a><a href="/industry/mini-markets-grab-n-go" class="c-footer_link">Grab & Go</a><a href="/industry/healthcare" class="c-footer_link">Healthcare</a><a href="/industry/cafes-business-dining" class="c-footer_link">Cafe Dining</a><a href="/industry/ski-resorts" class="c-footer_link">Ski Resorts</a></div><div id="w-node-_7a304a7d-8d29-13df-18d2-1581bf714368-bf71433d" class="c-wrap cc-gap_2"><div class="c-footer_heading">Resources</div><a href="/resources/mashgin-case-studies" class="c-footer_link">Customer Stories</a><a href="/skip-the-line-podcast" class="c-footer_link">Podcast</a><a href="/content/mashgin-university" class="c-footer_link">Mashgin University</a><a href="/resources/news" class="c-footer_link">News</a><a href="https://blog.mashgin.com/ai-retail" class="c-footer_link">Blog</a><a href="/resources/faq" class="c-footer_link">FAQ</a></div><div id="w-node-_7a304a7d-8d29-13df-18d2-1581bf714375-bf71433d" class="c-wrap cc-gap_2"><div class="c-footer_heading">Company</div><a href="/about" class="c-footer_link">About Us</a><a href="/careers" class="c-footer_link">Careers</a><a href="/company/fraudulent-recruitment" class="c-footer_link">Recruitment Fraud</a><a href="/contact" class="c-footer_link">Request Demo</a><a href="/company/press-inquires" class="c-footer_link">Press Inquiries</a></div><div id="w-node-_7a304a7d-8d29-13df-18d2-1581bf71437e-bf71433d" class="c-wrap cc-gap_2"><div class="c-footer_heading">Support</div><a href="/about" class="c-footer_link">help@mashgin.com</a><a href="https://mashgin.service-now.com/kb" target="_blank" class="c-footer_link">Knowledge Base</a><a href="https://docs.google.com/forms/d/e/1FAIpQLSfxHVCeHKhh1gddLrqxm7Oq-SSVZ9z94ztGe0_xzegcNFiBIw/viewform" target="_blank" class="c-footer_link">Manage My Data</a></div><div id="w-node-_7a304a7d-8d29-13df-18d2-1581bf714387-bf71433d" class="c-2x1"><div id="w-node-_7a304a7d-8d29-13df-18d2-1581bf714388-bf71433d" class="c-wrap cc-horizontal"><a href="https://www.linkedin.com/company/mashgin/" target="_blank" class="c-wrap w-inline-block"><div class="c-footer_social w-embed"><svg width="100%" height="100%" viewBox="0 0 39 38" fill="none" xmlns="http://www.w3.org/2000/svg">
<rect x="1.41406" y="0.5" width="37" height="37" rx="18.5" stroke="currentcolor"/>
<g clip-path="url(#clip0_3281_6208)">
<g clip-path="url(#clip1_3281_6208)">
<path d="M15.5781 15.9141H12.5781V26.9141H15.5781V15.9141Z" fill="currentcolor"/>
<path d="M14.0781 14.6641C15.0446 14.6641 15.8281 13.8806 15.8281 12.9141C15.8281 11.9476 15.0446 11.1641 14.0781 11.1641C13.1116 11.1641 12.3281 11.9476 12.3281 12.9141C12.3281 13.8806 13.1116 14.6641 14.0781 14.6641Z" fill="currentcolor"/>
<path d="M27.4948 26.9141H24.4948V21.3308C24.4948 17.9974 20.4948 18.2474 20.4948 21.3308V26.9141H17.5781V15.9141H20.5781V17.6641C21.9948 15.0808 27.5781 14.9141 27.5781 20.1641V26.9141H27.4948Z" fill="currentcolor"/>
</g>
</g>
<defs>
<clipPath id="clip0_3281_6208">
<rect width="100%" height="100%" fill="currentcolor" transform="translate(9.91406 9)"/>
</clipPath>
<clipPath id="clip1_3281_6208">
<rect width="100%" height="100%" fill="currentcolor" transform="translate(9.91406 9)"/>
</clipPath>
</defs>
</svg></div></a><a href="https://facebook.com/mashgin/" target="_blank" class="c-wrap w-inline-block"><div class="c-footer_social w-embed"><svg width="100%" height="100%" viewBox="0 0 39 38" fill="none" xmlns="http://www.w3.org/2000/svg">
<rect x="1.41406" y="0.5" width="37" height="37" rx="18.5" stroke="currentcolor"/>
<g clip-path="url(#clip0_3281_6216)">
<g clip-path="url(#clip1_3281_6216)">
<path d="M22.5135 13.4308H24.0802V10.7808C23.3216 10.7019 22.5595 10.6629 21.7969 10.6641C19.5302 10.6641 17.9802 12.0474 17.9802 14.5808V16.7641H15.4219V19.7307H17.9802V27.3307H21.0469V19.7307H23.5969L23.9802 16.7641H21.0469V14.8724C21.0469 13.9974 21.2802 13.4308 22.5135 13.4308Z" fill="currentcolor"/>
</g>
</g>
<defs>
<clipPath id="clip0_3281_6216">
<rect width="100%" height="100%" fill="currentcolor" transform="translate(9.91406 9)"/>
</clipPath>
<clipPath id="clip1_3281_6216">
<rect width="100%" height="100%" fill="currentcolor" transform="translate(9.91406 9)"/>
</clipPath>
</defs>
</svg></div></a><a href="https://instagram.com/checkoutmashgin/" target="_blank" class="c-wrap w-inline-block"><div class="c-footer_social w-embed"><svg width="100%" height="100%" viewBox="0 0 39 38" fill="none" xmlns="http://www.w3.org/2000/svg">
<rect x="1.41406" y="0.5" width="37" height="37" rx="18.5" stroke="currentcolor"/>
<g clip-path="url(#clip0_3281_6221)">
<g clip-path="url(#clip1_3281_6221)">
<path d="M24.3615 13.5474C24.1637 13.5474 23.9704 13.606 23.8059 13.7159C23.6415 13.8258 23.5133 13.982 23.4375 14.1647C23.3619 14.3474 23.3421 14.5485 23.3807 14.7425C23.4193 14.9365 23.5145 15.1147 23.6544 15.2545C23.7942 15.3944 23.9724 15.4896 24.1664 15.5282C24.3604 15.5668 24.5614 15.547 24.7441 15.4713C24.9269 15.3956 25.083 15.2674 25.193 15.103C25.3028 14.9385 25.3615 14.7452 25.3615 14.5474C25.3615 14.2822 25.2561 14.0278 25.0685 13.8403C24.881 13.6528 24.6267 13.5474 24.3615 13.5474ZM28.1948 15.5641C28.1786 14.8726 28.0491 14.1886 27.8115 13.5391C27.5995 12.9833 27.2698 12.4801 26.8448 12.0641C26.4321 11.6369 25.9278 11.3092 25.3698 11.1057C24.722 10.8609 24.0371 10.7284 23.3448 10.7141C22.4615 10.6641 22.1781 10.6641 19.9115 10.6641C17.6448 10.6641 17.3615 10.6641 16.4781 10.7141C15.7857 10.7284 15.1009 10.8609 14.4531 11.1057C13.8962 11.3113 13.3922 11.6387 12.9781 12.0641C12.551 12.4767 12.2233 12.9811 12.0198 13.5391C11.7749 14.1868 11.6425 14.8717 11.6281 15.5641C11.5781 16.4474 11.5781 16.7307 11.5781 18.9974C11.5781 21.2641 11.5781 21.5474 11.6281 22.4307C11.6425 23.1231 11.7749 23.808 12.0198 24.4557C12.2233 25.0137 12.551 25.5181 12.9781 25.9307C13.3922 26.3561 13.8962 26.6836 14.4531 26.8891C15.1009 27.1339 15.7857 27.2664 16.4781 27.2807C17.3615 27.3307 17.6448 27.3307 19.9115 27.3307C22.1781 27.3307 22.4615 27.3307 23.3448 27.2807C24.0371 27.2664 24.722 27.1339 25.3698 26.8891C25.9278 26.6856 26.4321 26.3579 26.8448 25.9307C27.2716 25.5162 27.6017 25.0126 27.8115 24.4557C28.0491 23.8062 28.1786 23.1221 28.1948 22.4307C28.1948 21.5474 28.2448 21.2641 28.2448 18.9974C28.2448 16.7307 28.2448 16.4474 28.1948 15.5641ZM26.6948 22.3307C26.6887 22.8597 26.593 23.3838 26.4115 23.8807C26.2784 24.2434 26.0647 24.5711 25.7865 24.8391C25.5161 25.1145 25.1891 25.3277 24.8281 25.4641C24.3312 25.6456 23.8071 25.7413 23.2781 25.7474C22.4448 25.7891 22.1365 25.7974 19.9448 25.7974C17.7531 25.7974 17.4448 25.7974 16.6115 25.7474C16.0622 25.7576 15.5153 25.6731 14.9948 25.4974C14.6496 25.3541 14.3376 25.1414 14.0781 24.8724C13.8015 24.6046 13.5905 24.2767 13.4615 23.9141C13.258 23.4101 13.1452 22.874 13.1281 22.3307C13.1281 21.4974 13.0781 21.1891 13.0781 18.9974C13.0781 16.8057 13.0781 16.4974 13.1281 15.6641C13.1319 15.1233 13.2306 14.5874 13.4198 14.0807C13.5665 13.729 13.7917 13.4154 14.0781 13.1641C14.3313 12.8775 14.6442 12.65 14.9948 12.4974C15.5027 12.3141 16.0381 12.2183 16.5781 12.2141C17.4115 12.2141 17.7198 12.1641 19.9115 12.1641C22.1031 12.1641 22.4115 12.1641 23.2448 12.2141C23.7738 12.2201 24.2979 12.3159 24.7948 12.4974C25.1735 12.6379 25.5134 12.8664 25.7865 13.1641C26.0595 13.42 26.273 13.733 26.4115 14.0807C26.5967 14.5882 26.6925 15.1239 26.6948 15.6641C26.7365 16.4974 26.7448 16.8057 26.7448 18.9974C26.7448 21.1891 26.7365 21.4974 26.6948 22.3307ZM19.9115 14.7224C19.0663 14.724 18.2406 14.9762 17.5387 15.4469C16.8367 15.9177 16.2901 16.5859 15.9678 17.3672C15.6455 18.1485 15.5621 19.0078 15.728 19.8365C15.8938 20.6652 16.3017 21.4261 16.8999 22.0232C17.4981 22.6202 18.2598 23.0266 19.0889 23.1908C19.9179 23.3551 20.777 23.27 21.5577 22.9461C22.3384 22.6224 23.0055 22.0744 23.4749 21.3716C23.9443 20.6687 24.1948 19.8426 24.1948 18.9974C24.1959 18.435 24.0858 17.8779 23.8708 17.3582C23.6559 16.8385 23.3403 16.3664 22.9422 15.9691C22.5441 15.5718 22.0714 15.2571 21.5513 15.0432C21.0311 14.8292 20.4739 14.7202 19.9115 14.7224ZM19.9115 21.7724C19.3626 21.7724 18.8261 21.6096 18.3698 21.3047C17.9134 20.9998 17.5577 20.5664 17.3477 20.0593C17.1377 19.5523 17.0827 18.9943 17.1898 18.456C17.2969 17.9177 17.5612 17.4232 17.9492 17.0352C18.3373 16.6471 18.8318 16.3828 19.37 16.2757C19.9084 16.1686 20.4664 16.2236 20.9734 16.4336C21.4805 16.6437 21.9139 16.9993 22.2188 17.4557C22.5237 17.9121 22.6865 18.4486 22.6865 18.9974C22.6865 19.3618 22.6147 19.7226 22.4752 20.0593C22.3358 20.3961 22.1314 20.7019 21.8737 20.9596C21.616 21.2173 21.3101 21.4217 20.9734 21.5611C20.6367 21.7006 20.2759 21.7724 19.9115 21.7724Z" fill="currentcolor"/>
</g>
</g>
<defs>
<clipPath id="clip0_3281_6221">
<rect width="100%" height="100%" fill="currentcolor" transform="translate(9.91406 9)"/>
</clipPath>
<clipPath id="clip1_3281_6221">
<rect width="100%" height="100%" fill="currentcolor" transform="translate(9.91406 9)"/>
</clipPath>
</defs>
</svg></div></a><a href="https://twitter.com/mashgin" target="_blank" class="c-wrap w-inline-block"><div class="c-footer_social w-embed"><svg width="100%" height="100%" viewBox="0 0 39 38" fill="none" xmlns="http://www.w3.org/2000/svg">
<rect x="1.41406" y="0.5" width="37" height="37" rx="18.5" stroke="currentcolor"/>
<g clip-path="url(#clip0_3281_6226)">
<g clip-path="url(#clip1_3281_6226)">
<path d="M28.2448 13.8325C27.6184 14.1043 26.956 14.2839 26.2781 14.3659C26.9933 13.9386 27.5292 13.2665 27.7865 12.4742C27.1145 12.8743 26.3788 13.1561 25.6115 13.3075C25.0985 12.7513 24.4156 12.3811 23.6696 12.2549C22.9237 12.1287 22.1569 12.2537 21.4896 12.6102C20.8223 12.9667 20.2922 13.5346 19.9825 14.2249C19.6727 14.9152 19.6009 15.6887 19.7781 16.4242C18.4193 16.3555 17.0902 16.0017 15.877 15.3858C14.6638 14.7698 13.5938 13.9056 12.7365 12.8492C12.4357 13.3743 12.2777 13.9691 12.2781 14.5742C12.2771 15.1362 12.415 15.6897 12.6796 16.1855C12.9442 16.6813 13.3273 17.104 13.7948 17.4158C13.2514 17.4011 12.7197 17.2553 12.2448 16.9909V17.0325C12.2489 17.8199 12.5248 18.5818 13.0259 19.1892C13.527 19.7966 14.2225 20.2123 14.9948 20.3658C14.6975 20.4563 14.3889 20.504 14.0781 20.5075C13.863 20.505 13.6485 20.4855 13.4365 20.4492C13.6564 21.1265 14.082 21.7185 14.654 22.1427C15.2261 22.5668 15.9161 22.8022 16.6281 22.8158C15.4258 23.7619 13.9414 24.2783 12.4115 24.2825C12.1329 24.2834 11.8546 24.2668 11.5781 24.2325C13.1401 25.2411 14.9605 25.7764 16.8198 25.7742C18.1029 25.7875 19.3757 25.545 20.564 25.0609C21.7524 24.5768 22.8323 23.8608 23.7408 22.9546C24.6493 22.0484 25.3681 20.9703 25.8553 19.7833C26.3425 18.5962 26.5881 17.324 26.5781 16.0409C26.5781 15.8992 26.5781 15.7492 26.5781 15.5992C27.232 15.1115 27.796 14.5137 28.2448 13.8325Z" fill="currentcolor"/>
</g>
</g>
<defs>
<clipPath id="clip0_3281_6226">
<rect width="100%" height="100%" fill="currentcolor" transform="translate(9.91406 9)"/>
</clipPath>
<clipPath id="clip1_3281_6226">
<rect width="100%" height="100%" fill="currentcolor" transform="translate(9.91406 9)"/>
</clipPath>
</defs>
</svg></div></a><a href="https://youtube.com/mashgin" target="_blank" class="c-wrap w-inline-block"><div class="c-footer_social w-embed"><svg width="100%" height="100%" viewBox="0 0 39 38" fill="none" xmlns="http://www.w3.org/2000/svg">
<rect x="1.41406" y="0.5" width="37" height="37" rx="18.5" stroke="currentcolor"/>
<g clip-path="url(#clip0_3281_6231)">
<g clip-path="url(#clip1_3281_6231)">
<g clip-path="url(#clip2_3281_6231)">
<path d="M29.0828 17.0899C29.1241 15.8972 28.8633 14.7133 28.3245 13.6483C27.959 13.2113 27.4518 12.9164 26.8912 12.8149C24.5724 12.6046 22.2442 12.5183 19.9162 12.5566C17.5967 12.5166 15.2768 12.6 12.9662 12.8066C12.5094 12.8897 12.0866 13.104 11.7495 13.4233C10.9995 14.1149 10.9162 15.2983 10.8329 16.2983C10.712 18.0962 10.712 19.9003 10.8329 21.6983C10.857 22.2611 10.9408 22.8198 11.0829 23.365C11.1833 23.7858 11.3866 24.1752 11.6745 24.4983C12.0139 24.8345 12.4465 25.061 12.9162 25.1483C14.7128 25.37 16.523 25.462 18.3328 25.4233C21.2495 25.465 23.8078 25.4233 26.8328 25.19C27.3141 25.108 27.7588 24.8812 28.1078 24.54C28.3412 24.3065 28.5154 24.0209 28.6162 23.7066C28.9143 22.7921 29.0606 21.835 29.0495 20.8733C29.0828 20.4066 29.0828 17.59 29.0828 17.0899ZM18.0329 21.3733V16.2149L22.9662 18.8066C21.5828 19.5733 19.7578 20.44 18.0329 21.3733Z" fill="currentcolor"/>
</g>
</g>
</g>
<defs>
<clipPath id="clip0_3281_6231">
<rect width="100%" height="100%" fill="currentcolor" transform="translate(9.91406 9)"/>
</clipPath>
<clipPath id="clip1_3281_6231">
<rect width="100%" height="100%" fill="currentcolor" transform="translate(9.91406 9)"/>
</clipPath>
<clipPath id="clip2_3281_6231">
<rect width="20" height="20" fill="currentcolor" transform="translate(9.91406 9)"/>
</clipPath>
</defs>
</svg></div></a></div><p href="#" id="w-node-_7a304a7d-8d29-13df-18d2-1581bf714393-bf71433d" class="c-footer_link">© 2025 All rights reserved</p></div><div class="c-footer_line"></div></div></section><div class="w-embed"><style>
body {
font-size: 1vw;
}
/* 9px body font size below 767px screens */
@media only screen and (max-width: 767px) {
body {font-size: 9px;}
}
/* Link color inherits from parent font color */
a {
color: inherit;
}
.w-dropdown-toggle {
color: inherit;
}
input, textarea, select {
-webkit-appearance: none;
-moz-appearance: none;
appearance: none; border-radius: 0;
background-image: none;
h1, h2, h3, h4, h5, h6 {
text-wrap: balance;
}
</style>
<!-- Buttons -->
<style>
/* ===== Staggered letter-by-letter hover swap for .c-button =====
- Text + arrow color always inherit from .c-button
- Control colors only via:
.c-button { color: ...; background: ... }
.c-button:hover { color: ...; background: ... }
- Transparent variant (.cc-transparent) keeps text white on hover
*/
/* Base button */
.c-button {
--speed: 280ms;
--easing: cubic-bezier(.2,.8,.2,1);
--stagger: 28ms;
display: inline-flex;
align-items: center;
gap: 0.5rem;
text-decoration: none;
/* Set your defaults here */
color: #000000; /* base text/arrow color */
background: #e7f61c; /* base background (example) */
}
/* Default hover (text/arrow color can change here if you want) */
.c-button:hover,
.c-button:focus-visible {
color: #000000; /* hover text/arrow color */
outline: none;
}
/* Label container */
.c-button_text {
display: inline-flex;
overflow: hidden;
white-space: nowrap;
}
/* Per-character wrapper (created by JS) */
.c-button_char {
display: inline-block;
position: relative;
overflow: hidden;
}
/* Two stacked copies of each character */
.c-button_char > span {
display: block;
will-change: transform;
transition-property: transform, color;
transition-duration: var(--speed);
transition-timing-function: var(--easing);
transition-delay: calc(var(--i, 0) * var(--stagger)); /* per-letter stagger */
transform: translate3d(0,0,0);
color: inherit; /* inherit from .c-button */
}
/* Top copy visible initially */
.c-button_char > span:first-child {
transform: translateY(0%);
}
/* Bottom copy starts hidden below */
.c-button_char > span:last-child {
position: absolute;
inset: 0 auto auto 0; /* align top/left; width follows content */
transform: translateY(100%);
}
/* Hover/focus: swap the two copies */
.c-button:hover .c-button_char > span:first-child,
.c-button:focus-visible .c-button_char > span:first-child {
transform: translateY(-100%);
}
.c-button:hover .c-button_char > span:last-child,
.c-button:focus-visible .c-button_char > span:last-child {
transform: translateY(0%);
}
/* Arrow micro-interaction (optional) */
.c-button_arrow {
transition: transform var(--speed) var(--easing);
}
.c-button:hover .c-button_arrow,
.c-button:focus-visible .c-button_arrow {
transform: translateX(2px);
}
/* Transparent variant: keep text white on hover */
.c-button.cc-transparent {
background: transparent;
color: #ffffff; /* base */
}
.c-button.cc-transparent:hover,
.c-button.cc-transparent:focus-visible {
color: #ffffff; /* stay white on hover */
}
/* Reduced motion */
@media (prefers-reduced-motion: reduce) {
.c-button_char > span,
.c-button_arrow {
transition: none;
}
}
</style></div><script src="https://d3e54v103j8qbb.cloudfront.net/js/jquery-3.5.1.min.dc5e7f18c8.js?site=603557fca6b5097977fbac59" type="text/javascript" integrity="sha256-9/aliU8dGd2tb6OSsuzixeV4y/faTqgFtohetphbbj0=" crossorigin="anonymous"></script><script src="https://cdn.prod.website-files.com/603557fca6b5097977fbac59/js/webflow.schunk.e0c428ff9737f919.js" type="text/javascript" integrity="sha384-ar82P9eriV3WGOD8Lkag3kPxxkFE9GSaSPalaC0MRlR/5aACGoFQNfyqt0dNuYvt" crossorigin="anonymous"></script><script src="https://cdn.prod.website-files.com/603557fca6b5097977fbac59/js/webflow.schunk.7e0e4571fdaccd05.js" type="text/javascript" integrity="sha384-amCQXi6xc/lezhwCxyktej7Ve0y0kAdyuyeX5Mrya3yFdTeB335L1rVX9NyRfPqi" crossorigin="anonymous"></script><script src="https://cdn.prod.website-files.com/603557fca6b5097977fbac59/js/webflow.d1711e37.660c9a7f4b0c2f58.js" type="text/javascript" integrity="sha384-KxrFkN6w802uMKjC9eb9onGaX8aieytTTYWmDzLx4y8ShoyyOkdq08e9ap+LICmx" crossorigin="anonymous"></script><!-- Google Tag Manager (noscript) -->
<noscript><iframe src="https://www.googletagmanager.com/ns.html?id=GTM-W2V7C3K"
height="0" width="0" style="display:none;visibility:hidden"></iframe></noscript>
<!-- End Google Tag Manager (noscript) -->
<!-- Start of HubSpot Embed Code -->
<script type="text/javascript" id="hs-script-loader" async defer src="//js-na1.hs-scripts.com/21903704.js"></script>
<!-- End of HubSpot Embed Code -->
<!-- Metadata Javascript - Insights Start -->
<script> (function(options) { var s = document.createElement("script"); s.async = true; s.src = "https://cdn.metadata.io/site-insights.js"; s.onload = function() { window.Metadata.siteInsights.init(options); }; document.head.appendChild(s); })({ accountId: 4220 }); </script>
<!-- Metadata Javascript - Insights End --></body></html>