This Data Processing Agreement (“DPA”) forms part of the Wartiva Subscription Agreement or other agreement for Wartiva services entered into between the Parties (the “Agreement”) between the Wartiva entity that has entered into the Agreement (“Wartiva”, “Us”, “We”, “Our”) and Customer (collectively, “You”, “Your”, or “Customer”) pursuant to the Agreement. Both parties shall be referred to as the “Parties” and each, a “Party”. This DPA forms a binding legal agreement to reflect the Parties’ agreement with regard to the Processing of Personal Data (as such terms are defined below).
WHEREAS, Wartiva shall provide the services set forth in the Agreement (collectively, the “Services”) to Customer, as described in the Agreement; and
WHEREAS, the Parties wish to set forth the arrangements concerning the Processing of Personal Data within the context of the Services and agree to comply with the following provisions with respect to any Personal Data, each acting reasonably and in good faith.
NOW THEREFORE, in consideration of the mutual promises set forth herein and other good and valuable consideration, the receipt and sufficiency of which are hereby acknowledged by the Parties, the Parties, intending to be legally bound, agree as follows:
1. INTERPRETATION AND DEFINITIONS
1.1 The headings contained in this DPA are for convenience only and shall not be interpreted to limit or otherwise affect the provisions of this DPA. References to clauses or sections are references to the clauses or sections of this DPA unless otherwise stated. Words used in the singular include the plural and vice versa, as the context may require. Capitalized terms not defined herein shall have the meanings assigned to such terms in the Agreement.
1.2 Definitions:
a. “Controller” or “Business” as relevant under applicable Data Protection Laws, means the entity which determines the purposes and means of the Processing of Personal Data or such equivalent term under Data Protection Laws.
b. “Customer Personal Data” means any Personal Data which is provided to and Processed by Wartiva on behalf of Customer in order to provide the Services under the Agreement. Customer Personal Data does not include Personal Data that Wartiva Processes as a Controller separately from its Processing obligations to Customer under the Agreement.
c. “Data Protection Laws” means all laws and regulations of the European Union, the EEA and their Member States, Switzerland, the United Kingdom, and the United States, each to the extent applicable to the Processing of Personal Data under the Agreement.
d. “Data Subject” means the identified or identifiable person to whom the Customer Personal Data relates.
e. “EEA” means the European Economic Area.
f. “EU Data Protection Law” means the GDPR, and the UK GDPR.
g. “Extended EEA Country” means a Member State of the EEA, Switzerland or the United Kingdom, and Extended EEA Countries means the foregoing countries collectively.
h. “Member State(s)” means a country that belongs to the European Union and/or the EEA.
i. “GDPR” means the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation).
j. “Personal Data” means any information relating to an identified or identifiable natural person; an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier or such equivalent term under Data Protection Laws.
k. “Process(ing)” means any operation or set of operations which is performed upon Personal Data, whether or not by automatic means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
l. “Processor” or “Service Provider,” as relevant under applicable Data Protection Laws, means the entity which Processes Personal Data on behalf of the Controller or Business or such equivalent term under Data Protection Laws.
m. “Security Addendum” means Wartiva’s Security Addendum which is available via https://wartiva.com/legal/sec-addendum.
n. “Standard Contractual Clauses” means the “standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council adopted by the European Commission decision of 4 June 2021” and published under document number C (2021) 3972 available at https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32021D0914&qid=1689513765256, as may be updated, amended or superseded from time to time.
o. “Sub-Processor” means any Processor or Service Provider engaged by Wartiva and/or Wartiva Affiliate to Process Customer Personal Data.
p. “Supervisory Authority” means the competent supervisory authority pursuant to the applicable Data Protection Laws.
q. “Third Country” has the meaning given in Clause 8.2 below.
r. “UK GDPR” means the GDPR as incorporated into United Kingdom domestic law pursuant to Section 3 of the European Union (Withdrawal) Act 2018 (the "UK GDPR").
s. “US Privacy Laws” means the California Consumer Privacy Act of 2018, Cal. Civ. Code § 1798.100 et seq., as amended by the California Privacy Rights Act of 2020 along with any associated regulations (“CCPA”); the Virginia Consumer Data Protection Act (“VCDPA”); the Colorado Privacy Act; and any similar U.S. laws governing data privacy and security once effective.
2. CUSTOMER’S PROCESSING OF PERSONAL DATA. Customer shall, in its use of the Services, Process Customer Personal Data in accordance with the requirements of Data Protection Laws. For the avoidance of doubt, Customer’s instructions for the Processing of Customer Personal Data shall comply with Data Protection Laws. As between the Parties, Customer shall have sole responsibility for the means by which Customer acquired Customer Personal Data. Without limitation, to the extent applicable, Customer shall comply with any and all transparency-related obligations (including, without limitation, displaying any and all relevant and required privacy notices or policies) and shall have any and all required legal basis in order to collect, Process and transfer to Wartiva the Customer Personal Data and to authorize the Processing by Wartiva of the Customer Personal Data which is authorized in this DPA.
3. WARTIVA’S PROCESSING OF PERSONAL DATA
3.1 Application. As used in clauses 3 – 9 herein, Customer Personal Data refers to Customer Personal Data that is subject to Data Protection Laws.
3.2 Roles of the Parties. The Parties acknowledge and agree that with regard to the Processing of Customer Personal Data, (i) Customer is the Controller or Business or, where Customer is acting behalf of its own customers, a Processor, (ii) Wartiva is the Processor or Service Provider, and (iii) Wartiva or its Affiliates may engage Sub-Processors pursuant to the requirements set forth in Clause 6 below.
3.3 Wartiva and its Affiliates (as applicable) shall Process Customer Personal Data only in accordance with Customer’s documented instructions, which are set out in the Agreement, as necessary for the performance of the Services and for the performance of the Agreement and this DPA, unless required to otherwise by any applicable law, court of competent jurisdiction or other Supervisory Authority to which Wartiva and its Affiliates are subject, in which case, Wartiva shall inform Customer of the legal requirement before processing, unless that law prohibits such information. Customer agrees that the Agreement is its complete and final instructions to Wartiva in relation to the Processing of Personal Data. Processing any Personal Data outside the scope of the Agreement will require prior written agreement between Wartiva and Customer by way of an amendment to the Agreement, and may include any additional fees that may be payable by Customer to Wartiva for carrying out such instructions. The duration of the Processing, the nature and purposes of the Processing, as well as the types of Customer Personal Data Processed and categories of Data Subjects under this DPA are further specified in Schedule 1 to this DPA.
3.4 To the extent that Wartiva or its Affiliates cannot comply with an instruction from Customer and/or its authorized users relating to Processing of Customer Personal Data or where Wartiva considers such instruction to be unlawful, Wartiva (i) shall inform Customer, providing relevant details of the problem; (ii) may, without any kind of liability towards Customer, temporarily cease all Processing of the affected Customer Personal Data (other than securely storing those data); and (iii) if the Parties do not agree on a resolution to the issue in question and the costs thereof, each Party may, as its sole remedy, terminate the Agreement and this DPA with respect to the affected Processing, and Customer shall pay to Wartiva all the amounts owed to Wartiva or due before the date of termination.
4. RIGHTS OF DATA SUBJECTS. If Wartiva receives a request from a Data Subject to exercise its rights under Data Protection Laws (“Data Subject Request”), Wartiva shall, to the extent legally permitted, promptly notify and forward such Data Subject Request to Customer. Taking into account the nature of the Processing, Wartiva shall use commercially reasonable efforts to assist Customer by appropriate technical and organizational measures, insofar as this is possible, for the fulfilment of Customer’s obligation to respond to a Data Subject Request under Data Protection Laws.
5. WARTIVA PERSONNEL
5.1 Confidentiality. Wartiva shall grant access to the Customer Personal Data to persons under its authority (including, without limitation, its personnel) only on a need-to-know basis and ensure that such persons engaged in the Processing of Customer Personal Data have committed themselves to confidentiality.
6. AUTHORIZATION REGARDING SUB-PROCESSORS
6.1 Customer hereby grants general written authorization to Wartiva to appoint Sub-Processors to perform specific Processing activities on Customer Personal Data on its behalf.
6.2 Where Wartiva engages a Sub-Processor, we shall do so by way of a written contract which imposes on the Sub-Processor substantially the same data protection obligations as in this DPA.
7. SECURITY
7.1 Controls for the Protection of Customer Personal Data. Taking into account the state of the art, Wartiva shall maintain industry-standard technical and organizational measures, including as required pursuant to Article 32 of the GDPR and other applicable Data Protection Laws, for protection of the security (including protection against unauthorized or unlawful Processing and against accidental or unlawful destruction, loss or alteration or damage, unauthorized disclosure of, or access to, Customer Personal Data), confidentiality and integrity of Customer Personal Data, as set forth in the Security Addendum. Upon Customer’s request, Wartiva will use commercially reasonable efforts to assist Customer, in ensuring compliance with the obligations pursuant to Articles 32 to 36 of the GDPR and other applicable Data Protection Laws taking into account the nature of the processing, the state of the art, the costs of implementation, the scope, the context, the purposes of the Processing and the information available to Wartiva.
8. TRANSFERS OF DATA
8.1 Transfers to countries that offer adequate level of data protection. Personal Data may be transferred from the Extended EEA Countries to countries or frameworks that offer adequate level of data protection under or pursuant to the adequacy decisions published by the relevant data protection authorities of the Extended EEA Countries (“Adequacy Decisions”), without any further safeguard being necessary.
8.2 Transfers to other countries. If, and to the extent, the Processing of Customer Personal Data which is subject to Data Protection Laws of the EEA Extended Countries includes transfers by Customer from the Extended EEA Countries to Wartiva in countries outside the Extended EEA Countries which have not been subject to an Adequacy Decision (“Third Countries”), the Parties agree that such transfers shall be undertaken on the basis of the Standard Contractual Clauses, which will be deemed to have been signed by each Party on the Effective Date of this Agreement, are incorporated herein by reference and construed in accordance with Schedule 2 below, unless another mechanism provided for in the Data Protection Laws of the applicable Extended EEA Country applies.
8.3 In the event Customer enables Third Party Integrations (as defined in the Agreement) which involve transfers of Customer Personal Data between Wartiva and the Third Party Integration provider, Customer acknowledges and agrees that (a) such Third Party Integration providers are not Sub-Processors of Wartiva; (b) such transfers are conducted at Customer’s instruction in accordance with an agreement between the Customer and such Third Party Integration provider (which Wartiva is not a party to); and (c) Customer shall be solely responsible for such transfers and their compliance with Data Protection Laws, including without limitation, executing Standard Contractual Clauses with such Third Party Integration providers as required.
9. US PRIVACY LAWS
9.1 In performing its obligations under the Agreement and this DPA, Wartiva shall comply with its obligations under US Privacy Laws, including by providing the level of privacy protection as is required by US Privacy Laws to Customer Personal Data subject to the US Privacy Laws. Wartiva will not: (1) “sell” or “share” for purposes of “cross-context behavioral advertising” or “targeted advertising” (as defined by applicable US Privacy Laws) any Customer Personal Data; (2) retain, use, or disclose Customer Personal Data for any purpose other than the contractual business purpose set forth herein or as otherwise permitted under US Privacy Laws or outside of the direct business relationship between Wartiva and Customer; or (3) attempt to re-identify any pseudonymized, anonymized, aggregate, or de-identified Customer Personal Data.
9.2 Wartiva will (1) comply with any applicable restrictions under applicable US Privacy Laws on combining Customer Personal Data with Personal Data that Wartiva receives from, or on behalf of, another person or persons; and (2) promptly notify Customer if Wartiva determines that it (i) can no longer meet its obligations under this DPA or applicable US Privacy Laws; or (ii) in Wartiva’s opinion, an instruction from Customer infringes applicable US Privacy Laws.
9.3 To the extent required under US Privacy Laws, Customer may take reasonable and appropriate steps to help to ensure that Wartiva uses Customer Personal Data in a manner consistent with Customer’s obligations under US Privacy Laws and to stop and remediate unauthorized use of the Customer Personal Data.
9.4 Wartiva certifies that it understands its obligations in this Clause 9.The Parties agree that Schedule 1 hereto shall satisfy any requirement under applicable U.S. Privacy Law to provide details regarding the nature of the Processing activities related to Customer Personal Data.
10. PERSONAL DATA INCIDENT MANAGEMENT AND NOTIFICATION. To the extent required under applicable Data Protection Laws, Wartiva shall notify Customer without undue delay after becoming aware of the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data (a “Personal Data Incident”). Wartiva shall make reasonable efforts to identify the cause of such Personal Data Incident and take those steps as Wartiva deems necessary, possible and reasonable in order to remediate the cause of such a Personal Data Incident. Customer (or its customers), as the Controller or Business, will be the party responsible for notifying supervisory authorities and/or concerned Data Subjects (where required by Data Protection Laws).
11. RETURN AND DELETION OF PERSONAL DATA. Subject to the Agreement, upon termination or expiry of the Services, Wartiva shall, make available for return the Customer Personal Data via the Services and delete such Customer Personal Data in accordance with Wartiva’s customer data retention & deletion policy unless applicable law requires storage of the Customer Personal Data. In any event, Customer agrees that Wartiva may retain Customer Personal Data in accordance with its standard backup policy, for evidence purposes and/or for the establishment, exercise or defense of legal claims and/or to comply with applicable laws and regulations.
12. TERMINATION. This DPA shall automatically terminate upon the termination or expiration of the Agreement under which the Services are provided, provided that, to the extent Wartiva retains any Customer Personal Data following termination or expiration of the Agreement, this DPA shall survive for such period that Wartiva retains Customer Personal Data. Clauses 2, 3.4 and 13 shall survive the termination or expiration of this DPA for any reason. This DPA cannot, in principle, be terminated separately to the Agreement, except where the Processing ends before the termination of the Agreement, in which case, this DPA shall automatically terminate.
13. RELATIONSHIP WITH AGREEMENT. Subject to any provisions in Schedule 2 regarding governing law and choice of forum of the Standard Contractual Clauses, the governing law and choice of forum provision in the Agreement shall apply to this DPA. In the event of any conflict between the provisions of this DPA and the provisions of the Agreement, the provisions of this DPA shall prevail over the conflicting provisions of the Agreement. For the avoidance of doubt each Party’s and its Affiliates’ liability, taken together in the aggregate, arising out of or relating to this DPA, the Standard Contractual Clauses, Data Protection Laws and any other data protection agreements in connection with the Agreement (if any), shall be subject to any aggregate limitations on liability set out in the Agreement. NOTWITHSTANDING THE FOREGOING, IF CUSTOMER IS USING THE SERVICES FOR A FREE TRIAL, WARTIVA’S MAXIMUM AGGREGATE LIABILITY TO CUSTOMER UNDER OR RELATED TO THIS DPA SHALL BE CAPPED AT ONE THOUSAND DOLLARS US ($1,000 US).
14. AFFILIATES. Any Wartiva obligation hereunder may be performed (in whole or in part), and any Wartiva right (including invoice and payment rights) or remedy may be exercised (in whole or in part), by an Affiliate of Wartiva. To the extent that any of Customer’s Affiliate(s): (a) is subject to the Data Protection Laws; (b) provides Customer Personal Data to Wartiva in the context of the Services; and (c) is permitted to use the Services pursuant to the Agreement but has not signed its own agreement with Wartiva and is not a “Customer” as defined under the Agreement, the Parties acknowledge and agree that, by executing the Agreement, Customer enters into this DPA on behalf of itself and, in the name and on behalf of such Affiliates, subject to the following: (a) each Affiliate agrees to be bound by the obligations under this DPA and any violation of this DPA by an Affiliate shall be deemed a violation by Customer; (b) Customer shall remain exclusively responsible for coordinating all communication with Wartiva under the Agreement and shall be entitled to make and receive any communication in relation to this DPA on behalf of its Affiliates; and (c) Affiliates shall not be entitled to bring a claim directly against Wartiva. If an Affiliate seeks to assert a legal demand, action, suit, claim, proceeding or other forms of complaints or proceedings against Wartiva (“Affiliate Claim”): (i) Customer must bring such Affiliate Claim directly against Wartiva on behalf of such Affiliate, unless Data Protection Laws require the Affiliate be a party to such claim; and (ii) all Affiliate Claims shall be considered claims made by Customer and shall be subject to the limitation of liability set forth in the Agreement.
15. CHANGES IN LAWS. In the event that changes to this DPA are required as a result of changes in Data Protection Laws, including to update any Schedules or transfer mechanisms, the Parties shall co-operate in good faith to implement such changes to ensure that this DPA complies with such Data Protection Laws.
List of Schedules
SCHEDULE 1 – DETAILS OF THE PROCESSING
SCHEDULE 2 – STANDARD CONTRACTUAL CLAUSE
SCHEDULE 1
DETAILS OF THE PROCESSING
Subject matter.
Wartiva will Process Customer Personal Data as necessary to perform the Services pursuant to the Agreement, as further instructed by Customer in its use of the Services.
Nature and Purpose of Processing.
Performing the Agreement, this DPA and/or other contracts executed by the Parties, including, providing the Service(s) and support and technical maintenance to Customer and complying with documented reasonable instructions provided by Customer where such instructions are consistent with the terms of the Agreement.
Duration of Processing.
Subject to any section of the DPA and/or the Agreement dealing with the duration of the Processing and the consequences of the expiration or termination thereof, Wartiva will Process Customer Personal Data for the duration of the Agreement, unless otherwise agreed upon in writing.
Types of Customer Personal Data.
Customer determines the categories of any Customer Personal Data that is made accessible to Wartiva, which may include, without limitation, Customer Personal Data relating to the following categories:
Wartiva only stores metadata such as CVEs, misconfigurations, list of installed packages, operating system events, local user accounts, operating system object identifiers and (depending on the features used by Customer) logs and file paths. Depending on the Customer’s environment and naming conventions and features used by Customer, some Personal Data may be included in the metadata findings. For example, local user account names, logs and artifacts could include an individual’s name, associated email address, professional phone number and IP address as well as information about device and operating system and samples of findings to enable Customer to locate, verify and remediate the finding(s).
Customer acknowledges that Wartiva does not control which Customer Personal Data Customer shares with it in the context of the Services.
Categories of Data Subjects.
As part of providing the Services, Wartiva may process Customer Personal Data related to Customer’s customers or users, leads, employees and service providers, the extent of which is solely determined by Customer.
SCHEDULE 2
STANDARD CONTRACTUAL CLAUSES
1. Incorporation and interpretation of the Standard Contractual Clauses
1.1. In relation to transfers by Customer of Customer Personal Data which are subject to Data Protection Laws of the Extended EEA Countries to Wartiva in Third Countries, the parties agree that Module Two (Transfer controller to processor) or Module 3 (Transfer processor to processor) of the Standard Contractual Clauses shall apply, as applicable.
1.2. The Parties acknowledge that the information required to be provided in the Standard Contractual Clauses, including the appendices, is set out in Appendix 1 below.
1.3. If there is a conflict between the provisions of this Agreement and the Standard Contractual Clauses, the Standard Contractual Clauses will prevail, provided that, except to the extent prohibited by applicable law, the Standard Contractual Clauses shall be interpreted in accordance with and subject to this DPA and the Agreement, including without limitation, the provisions on limitation of liability, instructions, storage, erasure and return of Personal Data, audits and engagement of Sub-Processors.
1.4. If any provision or part-provision of this DPA or the Agreement causes the Standard Contractual Clauses to become an invalid export mechanism in the relevant Extended EEA Country, it shall be deemed deleted but that shall not affect the validity and enforceability of the rest of this Agreement and the parties shall negotiate in good faith to agree a replacement provision that, to the greatest extent possible, achieves the intended commercial result of the original provision.
1.5 Where requested by Wartiva, Customer shall provide reasonable assistance to Wartiva and be responsible for issuing such communications to Data Subjects and/or the Controller (to the extent Module Three applies) as are required in order for Wartiva to comply with its obligations under the Standard Contractual Clauses.
1.6. Notwithstanding anything to the contrary, where the applicable Extended EEA Country where the data exporter is established or from where the transferred personal data originated is the UK, template Addendum B.1.0 issued by the UK ICO and laid before Parliament in accordance with s119A of the Data Protection Act 2018 on 2 February 2022, as it is revised under Section 18 of those Mandatory Clauses, (the “UK Approved Addendum”) shall amend the Standard Contractual Clauses in respect of such transfers and Part 1 of the UK Approved Addendum shall be populated as set out below:
Table 1. The “start date” will be the date this DPA enters into force. The “Parties” are Customer as exporter Wartiva as importer.
Table 2. The “Addendum EU SCCs” are the modules and clauses of the Standard Contractual Clauses selected in relation to a particular transfer in accordance with paragraphs 1.1 and 1.2 of this Schedule.
Table 3. The “Appendix Information” is as set out in Appendix 1 to this Schedule.
Table 4. Neither party may end the UK Approved Addendum in accordance with its Section 19.
1.7. Except where paragraph 1.7 above applies, but notwithstanding anything else to the contrary, where the applicable Extended EEA Country where the data exporter is established or from where the transferred personal data originated is not a Member State of the European Union, references in the Standard Contractual Clauses to:
(a) “Member States of the European Union” shall refer to the applicable Extended EEA Country in which the data exporter is established or from where the transferred Personal Data originated (as applicable);
(b) “the GDPR” shall refer to the Data Protection Laws of the Extended EEA Country in which the data exporter is established or from where the Personal Data originated; and
(c) “supervisory authority” shall refer to the data protection authority in the Extended EEA Country as determined in Annex I(C) below.
Appendix 1 – Completion of the Standard Contractual Clauses
ANNEX I
| A. LIST OF THE PARTIES | |
|---|---|
| Data Exporter: | Name and address: Customer, as set out in the Agreement Contact details: As set out in the Agreement Activities relevant to the data transferred under these Clauses: Receipt of Wartiva Services, as set out in the Agreement and this DPA |
| Data Importer: | Name and address: Wartiva, as set out in the Agreement Contact details: Privacy Officer, legal@wartiva.com Activities relevant to the data transferred under these Clauses: Provision of Wartiva Services, as set out in the Agreement and this DPA |
| B. DETAILS OF PROCESSING/TRANSFER | |
| CATEGORIES OF DATA SUBJECTS | As described in Schedule 1 |
| CATEGORIES OF PERSONAL DATA | As described in Schedule 1 |
| SPECIAL CATEGORIES OF DATA (IF APPLICABLE) | Wartiva does not control which Personal Data Customer shares with it in the context of the Services. |
| FREQUENCY OF THE TRANSFER | As regular as is required to provide the Services |
| NATURE AND PURPOSE OF THE PROCESSING | As described in Schedule 1 |
| RETENTION | As described in Schedule 1 |
| C. COMPETENT SUPERVISORY AUTHORITY | |
| The competent supervisory authority shall be determined in accordance with Clause 13 of the Standard Contractual Clauses. Where an EU Representative has not been appointed by data exporter, the competent supervisory authority shall be the supervisory authority of the Netherlands. | |
| D. GOVERNING LAW AND CHOICE OF FORUM | |
| GOVERNING LAW | For the purposes of Clause 17 of the Standard Contractual Clauses the Parties select OPTION 1: the law of the Netherlands. |
| CHOICE OF FORUM | For the purposes of Clause 18 of the SCCs: the Parties select the courts of the Netherlands. |
| E. OTHER | |
| Where the Standard Contractual Clauses identify optional provisions (or provisions with multiple options) the following will apply: For Clause 7 (Docking Clause), the optional provision will apply. For Clause 9(a), option 2 (General Written Authorization) will apply and the time period for prior notice of Sub-Processor changes shall be as set out in this DPA. For Clause 11(a) (Redress) – the optional provision will not apply. |
ANNEX II – WARTIVA SECURITY MEASURES
The technical and organizational measures including technical and organizational measures to support the security of Personal Data incorporated into Annex II of the Standard Contractual Clauses shall be the technical and organizational security measures as described in Wartiva’s Security Addendum.
In addition, Wartiva agrees to the following compensating safeguards to protect such data to an equivalent level as required under the Data Protection Laws of the Extended EEA Countries to the extent required under the Standard Contractual Clauses:
Wartiva and Customer shall encrypt all transfers of the Customer Personal Data between them, and Wartiva shall encrypt any onward transfers it makes of such Customer Personal Data.
Wartiva will use reasonably available legal mechanisms to challenge any demands for Customer Personal Data access through national security process it receives as well as any non-disclosure provisions attached thereto.
Wartiva will promptly notify Customer of any government demands for Customer Personal Data, unless prohibited under applicable law. To the extent Wartiva is prohibited by law from providing such notification, Wartiva shall: (i) review each request on a case-by-case basis; (ii) use reasonable efforts to request that the confidentiality requirement be waived to enable Wartiva to notify the Customer and/or the appropriate Supervisory Authority competent for the Customer; and (iii) maintain evidence of any such attempt to have a confidentiality requirement waived.
Wartiva will promptly notify Customer if Wartiva can no longer comply with the applicable clauses in this Section. Wartiva shall not be required to provide Customer with specific information about why it can no longer comply, if providing such information is prohibited by applicable law. Such notice shall entitle Customer to terminate the Agreement (or, at Customer’s option, affected statements of work, order forms, and like documents thereunder) and receive a prompt pro-rata refund of any prepaid amounts thereunder.