Eve Legal
Eve Legal

Data Processing Addendum

This Data Processing Addendum (this “DPA”) governs the Order between Butler Labs Inc, dba Eve Legal (“Eve”) and the customer identified in the applicable Order (“Customer”), and is incorporated into and forms part of the Terms of Service or Master Service Agreement between Eve and Customer referencing this DPA (the “Agreement”). Capitalized terms used but not defined in this DPA have the meanings given to them in the Agreement. “Process,” “Processing” and “Processed” mean any operation performed on Customer Personal Data, whether or not by automated means.

Order of Precedence. In the event of a conflict between this DPA and the Agreement with respect to the Processing of Customer Personal Data, this DPA controls. In the event of a conflict between this DPA and the SCCs or the UK Addendum, the SCCs or the UK Addendum control, but only with respect to Customer Personal Data subject to European Data Protection Law. In all other respects the Agreement controls, including with respect to limitations of liability as provided in Section 10.1 below.

  1. Data Processing, Subject Matter, and Roles.

1.1. Data Processing. In the course of providing the Services to Customer pursuant to the Agreement, Eve may Process Customer Data that constitutes information that relates to an identified or identifiable living person, “personal data,” “personal information,” “personally identifiable information,” or an analogous term under any applicable law (“Customer Personal Data”). The Parties agree to comply with this DPA and all privacy and data protection laws applicable to their respective Processing of Customer Personal Data under the Agreement, including, as applicable, those of the European Union, the European Economic Area and their member states, Switzerland and the United Kingdom (collectively, “European Data Protection Law”); those of the United States, including the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act (the “CCPA”) and other applicable state privacy laws; and those of Canada, including the Personal Information Protection and Electronic Documents Act and, where applicable, Quebec’s Act respecting the protection of personal information in the private sector (collectively, “Data Protection Laws”). Each Party is responsible for its own compliance with Data Protection Laws applicable to it, and Eve is responsible only for those obligations expressly allocated to a Processor or Service Provider under this DPA. Data Protection Laws also include, without limitation: the comprehensive consumer privacy statutes of any other US state applicable to the Processing, including those of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Delaware, New Jersey, Minnesota and Maryland; US state statutes governing consumer health data, including the Washington My Health My Data Act and the Nevada Consumer Health Data Privacy Act; US state biometric privacy statutes, including the Illinois Biometric Information Privacy Act; and, in Canada, any provincial legislation declared substantially similar to the Personal Information Protection and Electronic Documents Act, including the Personal Information Protection Acts of Alberta and British Columbia.

1.2. Subject Matter. The subject matter, nature and purpose of the Processing, the types of Customer Personal Data, and the categories of “Data Subjects” (as such term is defined under applicable Data Protection Laws) are as described in the Agreement and, in respect of any International Data Transfer, in Annex I, each of which is an integral part of this DPA. Eve Processes Customer Personal Data for the duration of the Agreement and for the retention periods described in Section 6.

1.3. Roles. Customer is a “Controller” or “Business” (as such terms are defined under applicable Data Protection Law) and appoints Eve as a “Processor” or “Service Provider” (as such terms are defined under applicable Data Protection Law) on behalf of Customer. Customer is responsible for compliance with the requirements of Data Protection Law applicable to Controllers and Businesses. If Customer is a Processor on behalf of a Controller for which Customer is a Processor (“Third-Party Controller”), then Customer: (i) is the single point of contact for Eve; (ii) must obtain all necessary authorizations from such Third-Party Controller; and (iii) undertakes to issue all instructions and exercise all rights on behalf of such other Third-Party Controller. Customer represents and warrants that it has provided all notices and obtained all consents, authorizations and legal bases required under Data Protection Laws for Eve to Process Customer Personal Data as contemplated by the Agreement and this DPA. Eve is not responsible for determining whether a legal basis exists for any Processing, for maintaining Customer’s records of processing, or for conducting Customer’s data protection impact or risk assessments.

1.4. Processing Instructions. Eve will Process Customer Personal Data on behalf of and only in accordance with Customer’s documented instructions for the following purposes: (i) Processing in accordance with the DPA, Agreement, and applicable Order Form(s); (ii) Processing initiated by Users in their use of the Services; and (iii) Processing to comply with other documented reasonable instructions provided by Customer (e.g., via email) where such instructions are consistent with the terms of the Agreement. Eve will inform Customer if, in Eve’s reasonable opinion, an instruction infringes Data Protection Laws, and may suspend performance of that instruction until it is withdrawn, amended or confirmed in writing. Customer’s instructions are limited to Processing that is technically feasible within the standard functionality of the Services.

1.5. Personnel. Eve will ensure that all personnel authorized to Process Customer Personal Data are subject to an obligation of confidentiality.

1.6. US State Privacy Law Limitations on Processing. Except as permitted by applicable Data Protection Law, Eve will not: (a) retain, use, or disclose Customer Personal Data for any purpose other than performing the Services and in accordance with Customer’s documented instructions, including for Eve’s own commercial purposes; (b) retain, use, or disclose Customer Personal Data outside of the direct business relationship between the Parties; (c) combine Customer Personal Data with personal information that Eve receives from or on behalf of another person, or collects from its own interaction with a consumer, except as permitted by applicable Data Protection Law; and (d) “Sell” or “Share” (as such terms are defined under applicable Data Protection Laws) Customer Personal Data. Eve will notify Customer promptly if Eve determines that it can no longer meet its obligations under applicable US state Data Protection Law, and Customer may take reasonable and appropriate steps to stop and remediate any unauthorized use of Customer Personal Data. Customer acknowledges that Customer Personal Data may include “Sensitive Personal Information” as defined under the CCPA, including information concerning health, and that Eve will Process such information only as necessary to perform the Services and subject to the safeguards described in Annex II. Eve is also a “Processor” (or analogous role) under the comprehensive consumer privacy statutes of other US states, and will Process Customer Personal Data only on Customer’s behalf and in accordance with Customer’s instructions as required by those statutes. In satisfaction of the processor contract requirements of those statutes, Eve will: (i) ensure that persons Processing Customer Personal Data are subject to the duty of confidentiality described in Section 1.5; (ii) delete or return Customer Personal Data at Customer’s direction as described in Section 6; (iii) make available to Customer the reports and information described in Section 2.1 necessary to demonstrate Eve’s compliance with its obligations; (iv) permit and cooperate with assessments as described in Section 4.2; (v) engage Subprocessors only in accordance with Section 3; and (vi) provide the assistance described in Section 4.1 in relation to consumer rights requests, security of Processing, breach notification, and data protection assessments.

1.7. Deidentified and Aggregated Data. Eve may create, use, retain and disclose Deidentified Data and Aggregated Data derived from Customer Personal Data, during and after the Term.

(a) "Deidentified Data" means information that cannot reasonably be used to infer information about, or otherwise be linked to, a particular Data Subject, Customer, any client of Customer, or any Matter. "Aggregated Data" means information that relates to a group or category of Data Subjects from which individual identities have been removed and that is not linked or reasonably linkable to any Data Subject or household, including via a device; it does not include one or more individual records that have merely been deidentified.

(b) With respect to Deidentified Data and Aggregated Data, Eve will: (i) take reasonable measures to ensure that the information cannot be associated with any Data Subject, household, Customer, client of Customer, or Matter; (ii) publicly commit to maintain and use the information in deidentified form and not to attempt to reidentify it, except that Eve may attempt reidentification solely for the purpose of determining whether its deidentification processes satisfy the requirements of applicable Data Protection Law; (iii) contractually obligate any recipient of the information to comply with this Section 1.7; and (iv) not combine the information with any other information for the purpose of reidentifying any Data Subject.

(c) Deidentified Data and Aggregated Data are not Customer Personal Data or Customer Data and are not subject to Section 1.6. Nothing in this Section limits Eve's rights in respect of Usage Data under the Agreement.

(d) Where European Data Protection Law applies to the underlying Customer Personal Data, Eve will treat data as Deidentified Data only where it has been anonymized such that it no longer constitutes personal data under that law. Pseudonymized data remains Customer Personal Data.

1.8. Consumer Health Data. Customer Personal Data may include “consumer health data” as defined under applicable US state consumer health privacy laws, including the Washington My Health My Data Act and the Nevada Consumer Health Data Privacy Act. With respect to such data, Eve acts as a processor and not as a regulated entity or controller: Eve will Process consumer health data only in accordance with Customer’s instructions and only as necessary to provide the Services, will not collect, use, retain, share or disclose consumer health data for its own purposes, and will not sell consumer health data within the meaning of those laws. This DPA constitutes the binding contract required of a processor of consumer health data under those laws. Eve will not implement any geofence around any facility that provides in-person health care services.

2. Security and Security Incident.

2.1. Security. Eve will implement reasonable and appropriate technical and organizational measures designed to ensure a level of security appropriate to the risks presented by the Processing of Customer Personal Data in accordance with (a) the measures set forth in Annex II, and (b) SOC-2, ISO-27001, NIST 800-53 or a substantially equivalent standard during the Term.Upon Customer’s written request, no more than once every twelve (12) months, Eve will provide Customer with a copy of its then-current SOC 2 Type II report (or a substantially equivalent third-party audit report then maintained by Eve) covering the security of the systems used to process Customer Personal Data.Eve may comply with this obligation by providing Customer access to a security resource where Customer can obtain the then-current reports through self-service. Eve may update the measures described in Annex II from time to time, provided that no such update will materially reduce the overall level of security provided to Customer Personal Data during the Term.

2.2. Security Incident Notification. Eve will notify Customer without undue delay, and in any event within seventy-two (72) hours, after Eve confirms a Security Incident. “Security Incident” means a confirmed breach of Eve’s security leading to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of, or unauthorized access to, Customer Personal Data Processed by Eve. A Security Incident does not include an unsuccessful attempt or activity that does not compromise the security of Customer Personal Data, including unsuccessful log-in attempts, pings, port scans, denial-of-service attacks, or other network attacks on firewalls or networked systems. If Eve’s notification of a Security Incident is delayed, it will be accompanied by reasons for the delay.

2.3. Security Incident Response. Eve will take reasonable measures in response to a Security Incident, including (i) taking measures designed to mitigate any Security Incident and prevent the recurrence of the Security Incident, (ii) providing Customer with reasonable information relating to the Security Incident known to Eve, and (iii) providing other commercially reasonable assistance to Customer in complying with its obligations under applicable Data Protection Laws.

2.4. Notification Costs; No Admission. Eve’s obligation under Section 2.2 is to notify Customer. Eve has no obligation to notify any Data Subject, client of Customer, regulator, supervisory authority or other third party on Customer’s behalf, and will not do so without Customer’s prior written consent unless required by applicable law. Customer is solely responsible for determining whether notification is required and for the content, timing and cost of any such notification, including the cost of any credit monitoring, call center, forensic or remediation services Customer elects to provide. Eve’s notification of a Security Incident is not an acknowledgment by Eve of any fault or liability.

2.5. Vulnerability Testing. Eve will perform vulnerability scanning of Eve’s software-as-a-service platform used to provide the Services and will mitigate or remediate vulnerabilities identified in such scans in a commercially reasonable manner and timeframe based upon classified and prioritized severity levels.

2.6. Encryption. Eve will encrypt Customer Personal Data in accordance with industry accepted standards, strong encryption techniques, and current security protocols.

3. Subprocessing.

3.1. Subprocessors. Customer hereby authorizes Eve to engage any Processor that processes Customer Personal Data on behalf of Eve (“Subprocessor”). A list of Eve’s current Subprocessors is listed at www.eve.legal/subprocessors.Eve may update this list from time to time in accordance with this Agreement.

3.2. Subprocessor Agreements. Eve must enter into a written agreement with all Subprocessors which imposes substantially similar obligations on the Subprocessors as the obligations imposed on Eve under this DPA.

3.3. Subprocessor Changes. Eve will notify Customer at least thirty (30) days prior to any intended addition or replacement of a Subprocessor, which notice may be given by email or through a subscription mechanism made available by Eve. Customer may object to the addition or replacement of a Subprocessor on reasonable grounds that the appointment will result in a material violation of Data Protection Law, by providing written notice detailing the grounds of the objection within ten (10) days following Eve’s notice. The Parties will work together in good faith to address Customer’s objection, including by considering commercially reasonable alternatives. If the Parties are unable to resolve the objection within thirty (30) days and Eve elects to proceed with the Subprocessor, Customer may, as its sole and exclusive remedy, terminate the portion of the Services that cannot be provided without that Subprocessor by written notice to Eve, and Eve will refund any prepaid, unused fees for the terminated portion of those Services for the then-current Term. Notwithstanding the foregoing, Eve may engage a new Subprocessor without advance notice where reasonably necessary to maintain the security, integrity or continuity of the Services, in which case Eve will notify Customer promptly thereafter, or may offer Customer the ability to participate in Evaluation Use features that require a new Subprocessor, in which case Eve will notify Customer of the new Subprocessor prior to Customer’s Evaluation Use of the features.

3.4. Third-Party Model Providers. Certain Subprocessors identified in Annex III provide artificial intelligence models used to deliver the Services. Eve either (a) contracts with such Subprocessors on terms that require them to (1) Process Customer Personal Data solely to provide the applicable functionality to Eve, (2) not retain Customer Personal Data other than transiently as necessary for Processing, or to Process it through a zero-retention workflow or endpoint, (3) not use Customer Personal Data to train Subprocessor large language models offered to the public generally, and (4) not permit human review of Customer Personal Data except as necessary to provide the service and subject to obligations of confidentiality, or (b) is otherwise able to use configurations of such Subprocessors to meet the requirements of subsections (1)-(4) of subsection (a) above. No Subprocessor is permitted to use Customer Personal Data to train the Subprocessor’s artificial intelligence or machine learning model offered to the public generally.

4. Assistance.

4.1. Assistance. Taking into account the nature of the Processing and the information available to Eve, Eve will provide reasonable assistance to Customer in connection with Customer’s obligations under Data Protection Laws, including in implementing appropriate technical and organizational measures, responding to requests from Data Subjects or “Consumers” (as such term is defined under applicable Data Protection Laws), responding to inquiries, complaints and investigations, conducting data protection impact assessments and data protection risk assessments, and conducting prior consultations with regulators. Eve will provide such assistance at no charge to the extent it is required of a Processor or Service Provider under applicable Data Protection Law and can be satisfied through the standard functionality of the Services or Eve’s standard documentation. Any assistance beyond that scope will be provided, if at all, at Eve’s then-current professional services rates.

4.2. Audit. Customer’s audit rights under this DPA and applicable Data Protection Law will be satisfied in the first instance by Eve’s provision of the reports and documentation described in Section 2.1. If Customer reasonably determines that those reports are insufficient to demonstrate Eve’s compliance with this DPA, or if an audit is required by a supervisory authority or other regulatory authority responsible for the enforcement of Data Protection Law, then upon Customer’s reasonable written request Eve will permit Customer, at Customer’s expense, to audit Eve’s applicable controls and compliance with this DPA (an “Audit”), provided such Audit is (a) conducted on at least thirty (30) days’ prior written notice by Customer or a third-party auditor designated by Customer that is not a competitor of Eve and that has executed an appropriate confidentiality agreement with Eve; (b) conducted on reasonable details mutually agreed by Customer and Eve, including the start date, scope and duration of, and the security and confidentiality controls applicable to, such Audit; (c) conducted during Eve’s regular business hours, for no more than three (3) business days, and in a manner designed to minimize disruption to Eve’s business and to Eve’s other customers; and (d) not conducted where a similar Audit has already been conducted less than twelve (12) months prior, unless required by a supervisory authority. No Audit will extend to (i) Customer Personal Data or Confidential Information of any other Eve customer, (ii) Eve’s internal cost, pricing or personnel information, or (iii) any information subject to legal privilege or to obligations of confidentiality owed by Eve to a third party. Customer will pay any costs and expenses incurred by Eve in connection with any such Audit. Customer may use the results of an Audit only for the purposes of meeting Customer’s regulatory audit requirements and confirming compliance with the requirements of this DPA, and such results are Eve’s Confidential Information.

4.3. Data Subject Requests. If Eve receives a request from a Data Subject or Consumer relating to Customer Personal Data, Eve will not respond substantively to the request and will, to the extent permitted by applicable law, promptly redirect the request to Customer or inform the requester that the request should be directed to Customer. Customer is solely responsible for responding to such requests, including for verifying the identity of the requester and for determining whether any exception or exemption applies.

5. International Data Transfers.

5.1. European Data Transfers. This Section 5 applies only to the extent Eve Processes Customer Personal Data subject to European Data Protection Law. Customer hereby authorizes Eve to conduct transfers of such Customer Personal Data outside the EEA or Switzerland (an “International Data Transfer”):

  • to any country subject to a valid adequacy decision of the European Commission;
  • on the basis of an organization’s binding corporate rules approved by EEA Supervisory Authorities; and
  • to any data importer with whom Eve has entered into standard contractual clauses (“SCCs”).

5.2. European Transfer Mechanisms. To the extent an International Data Transfer is made on the basis of standard contractual clauses, Module 2 (Controller-to-Processor) of the SCCs applies and, to the extent Customer is a Processor on behalf of a Third-Party Controller, Module 3 (Processor-to-Subprocessor) of the SCCs applies, which are hereby incorporated and completed as follows: the “data exporter” is Customer; the “data importer” is Eve; the optional docking clause in Clause 7 is implemented; Option 2 (general written authorisation) of Clause 9(a) is implemented and the time period therein is thirty (30) days as specified in Section 3.3 above; the optional redress clause in Clause 11(a) is struck; Option 1 in Clause 17 is implemented and the governing law is the law of Ireland; the courts in Clause 18(b) are the courts of Ireland; Annex I to the SCCs is Annex I to this DPA, Annex II to the SCCs is Annex II to this DPA, and the list of Subprocessors referred to in the SCCs is Annex III to this DPA. For International Data Transfers from Switzerland, Data Subjects who have their habitual residence in Switzerland may bring claims under the SCCs before the courts of Switzerland, and references to the GDPR are to be understood as references to the Swiss Federal Act on Data Protection. In the event of a conflict between the SCCs and this DPA, the SCCs prevail with respect to Customer Personal Data subject to European Data Protection Law.

5.3. UK Data Transfers. Customer hereby authorizes Eve to perform International Data Transfers outside the UK subject to the requirements:

  • to any country subject to a valid adequacy decision issued by the UK Government;
  • on the basis of an organization’s binding corporate rules approved by the UK Information Commissioner; and
  • to any data importer with whom Eve has entered into the UK Addendum or other standard contractual clauses issued by the UK Information Commissioner, as appropriate.

5.4. UK Transfer Mechanism. Customer and Eve conclude the UK Addendum, which is hereby incorporated and applies to International Data Transfers outside the UK. Part 1 of the UK Addendum is completed as follows: (i) in Table 1, the “Exporter” is Customer and the “Importer” is Eve, and their details are set forth in this DPA and the Agreement; (ii) in Table 2, the first option is selected and the “Approved EU SCCs” are the SCCs referred to in Section 5.2 of this DPA; (iii) in Table 3, Annex 1A, Annex 1B and Annex II to the “Approved EU SCCs” are Annex I and Annex II to this DPA, and the list of Subprocessors is Annex III to this DPA; and (iv) in Table 4, neither the “Importer” nor the “Exporter” may end the UK Addendum as set out in Section 19 of the UK Addendum. In the event of a conflict between the UK Addendum and this DPA, the UK Addendum prevails with respect to Customer Personal Data subject to UK Data Protection Law.

5.5. Canada. To the extent Eve Processes Customer Personal Data subject to Canadian Data Protection Laws, Eve will use contractual and other means to provide a comparable level of protection while the information is being Processed by Eve or a Subprocessor. Upon Customer’s written request, Eve will provide information reasonably necessary for Customer to conduct a privacy impact assessment in connection with the communication of personal information outside Quebec, and will identify the jurisdictions in which Customer Personal Data is Processed. Customer acknowledges that Customer Personal Data is Processed in the United States as described in Annex III. This DPA constitutes the written agreement required in connection with the communication of personal information outside Quebec under applicable Quebec law, and the Parties will amend Annex II or this Section 5.5 as necessary to reflect measures agreed following Customer’s privacy impact assessment. On Customer’s request, Eve will provide the information reasonably necessary for Customer to maintain the record of breaches of security safeguards required under the Personal Information Protection and Electronic Documents Act and any register of confidentiality incidents required under Quebec law, and to notify individuals of Eve’s use of service providers outside Canada where required under applicable provincial legislation. Customer acknowledges that, as between the Parties, Customer is the organization having control of the Customer Personal Data for the purposes of Canadian Data Protection Laws and is responsible for any reporting to the Office of the Privacy Commissioner of Canada, the Commission d’accès à l’information du Québec, or any provincial commissioner.

6. Return and Deletion. Following expiration or earlier termination of the Agreement, Eve will make Customer Personal Data available for retrieval, and will delete Customer Personal Data, in accordance with the Agreement. Eve may retain copies of Customer Personal Data as expressly agreed by the Parties, as required by applicable law, or as contained in routine backups and data archives, which will be deleted in the ordinary course in accordance with Eve’s retention schedule and will remain subject to the protections of this DPA while retained. Upon Customer’s written request made within thirty (30) days following deletion, Eve will provide written confirmation that deletion has been completed in accordance with this Section. If Customer notifies Eve in writing that Customer Personal Data is subject to a litigation hold or other legal preservation obligation, Eve will preserve the identified Customer Personal Data in place, at Customer’s expense and in accordance with a mutually agreed scope and duration, and will not delete it until Customer confirms in writing that the hold has been released.

7. Privilege, Work Product and Client Confidentiality.

7.1. Acknowledgment. The Parties acknowledge that Customer Personal Data may include information subject to the attorney-client privilege, the work product doctrine, or obligations of confidentiality that Customer owes to its clients. Eve Processes such information solely as a Processor, at Customer’s direction, and for the purpose of providing the Services.

7.2. No Waiver. The Parties intend that no disclosure of Customer Personal Data to Eve, and no Processing by Eve or its Subprocessors under the Agreement, constitutes a waiver of any privilege, protection or immunity. Eve will not assert any right to use or disclose privileged or work product material other than as necessary to provide the Services, and will treat all such material as Customer’s Confidential Information under the Agreement. Customer is solely responsible for determining what material is privileged or otherwise protected and for asserting and preserving any such privilege or protection.

7.3. Personnel Access. Eve will limit access to Customer Personal Data to those personnel who require access in order to provide, secure or support the Services and will not access the substantive content of a Matter except as reasonably necessary to provide or support the Services, to investigate a Security Incident, or as directed or authorized by Customer.

8. Government and Third-Party Demands.

8.1. Notice. If Eve receives a subpoena, warrant, court order, discovery request or other legally binding demand from a government authority or third party seeking Customer Personal Data, Eve will, unless legally prohibited, (a) promptly notify Customer, (b) inform the requesting party that Eve is a Processor acting on Customer’s behalf and that the request should be directed to Customer, and (c) not produce Customer Personal Data before the earlier of the date required by law and the expiry of a reasonable period for Customer to seek a protective order or otherwise object.

8.2. Challenge. Where Eve is prohibited by law from notifying Customer of a demand, Eve will use reasonable efforts to obtain a waiver of the prohibition, and will challenge the demand where Eve reasonably determines there is a lawful basis to do so. Eve will produce only the minimum amount of Customer Personal Data necessary to respond.

8.3. Costs and Cooperation. Customer will reimburse Eve’s reasonable costs, including reasonable attorneys’ fees, incurred in responding to any such demand or in providing assistance to Customer in connection with it, except where the demand arises from Eve’s breach of this DPA. Eve will reasonably cooperate with Customer, at Customer’s expense, in any effort by Customer to assert a privilege or protection.

9. Customer Obligations and Warranties.

9.1. Lawfulness. Customer represents and warrants that (a) it has provided all notices and obtained all consents, authorizations and legal bases required under Data Protection Laws for the Processing contemplated by the Agreement and this DPA; (b) its instructions to Eve, and Processing performed in accordance with them, comply with Data Protection Laws; and (c) where Customer acts as a Processor on behalf of a Third-Party Controller, it has obtained all necessary authorizations from that Third-Party Controller.

9.2. Categories of Data. Customer will not submit Customer Personal Data to the Services other than as contemplated by the Agreement. Without limiting the foregoing, Customer will not submit protected health information where Customer is acting as a covered entity or business associate under HIPAA absent a business associate agreement executed by Eve, cardholder data subject to PCI DSS, or biometric or genetic identifiers, in each case except as expressly permitted in the applicable Order. Customer represents that it is not a covered entity or business associate under HIPAA in respect of the Customer Personal Data it submits to the Services.

9.3. Eve Not Responsible. Eve is not responsible for the accuracy, quality or legality of Customer Personal Data, for the means by which Customer acquired it, or for Customer’s compliance with the obligations applicable to Customer as a Controller, Business, or Processor on behalf of a Third-Party Controller.

9.4. Consumer Health Data. Where Customer Personal Data includes consumer health data relating to a resident of a state having a consumer health privacy law, Customer represents and warrants that it has obtained all consents and, where applicable, valid authorizations required under that law for the collection, Processing and sharing of such data as contemplated by the Agreement and this DPA, and that it will not instruct Eve to sell such data. Customer acknowledges that Customer is the regulated entity or controller with respect to consumer health data, that Eve relies on Customer’s determination of the lawful basis for Processing it, and that Customer is responsible for any notice, consent or authorization required in respect of it.

10. Liability; Term; Amendment.

10.1. Liability. Each Party’s liability arising out of or in connection with this DPA, the SCCs and the UK Addendum, whether in contract, tort or under any other theory of liability, is subject to the exclusions and limitations of liability set forth in the Agreement, and any reference in the Agreement to a Party’s aggregate liability means that Party’s aggregate liability under the Agreement and this DPA taken together. Nothing in this DPA, the SCCs or the UK Addendum increases or expands either Party’s liability beyond the limits set forth in the Agreement, except to the extent required by applicable Data Protection Law as between a Party and a Data Subject.

10.2. Term. This DPA takes effect on the effective date of the Agreement and continues until the Agreement expires or terminates, provided that the provisions of this DPA that by their nature should survive, including Sections 6, 7, 8, 9 and 10, survive for so long as Eve Processes or retains any Customer Personal Data.

10.3. Amendment. Eve may amend this DPA from time to time, including to reflect a change in Data Protection Laws, the adoption of a new or replacement transfer mechanism, or a change in Eve’s Subprocessors, provided that no such amendment will materially reduce the protections afforded to Customer Personal Data below the standard set by applicable Data Protection Law.

10.4. Governing Law. Except as otherwise provided in the SCCs and the UK Addendum, this DPA is governed by the law specified in the Agreement.

Annex I

ANNEX I

DESCRIPTION OF THE TRANSFER

  1. LIST OF PARTIES

Data exporter:

  • Name: Customer (as defined in the applicable Order)
  • Activities relevant to the data transferred under these Clauses: Customer receives Eve’s services as described in the Agreement and Customer provides Personal Data to Eve in that context.
  • Role (controller/processor): Controller, or Processor on behalf of Third-Party Controller

Data importer:

  • Name: Butler Labs, Inc, dba Eve
  • Activities relevant to the data transferred under these Clauses: Eve provides its services to Customer as described in the Agreement and Processes Personal Data on behalf of Customer in that context.
  • Role (controller/processor): Processor on behalf of Customer, or Subprocessor on behalf of Third-Party Controller

2. DESCRIPTION OF INTERNATIONAL DATA TRANSFER

Scope of this Annex I. This Annex I describes International Data Transfers of Customer Personal Data subject to European Data Protection Law. As of the Last Updated Date, Eve conducts no such transfers, and the descriptions below apply if and when such transfers occur. Eve will update this Annex I in accordance with Section 10.3 before, or promptly upon, commencing any International Data Transfer.

  • Categories of Data Subjects whose Customer Personal Data is transferred:
    • Customer’s customers
    • Customer’s personnel, staff and contractors
  • Categories of Customer Personal Data transferred:
    • Name
    • Contact details
  • Sensitive data transferred (if applicable) and applied restrictions or safeguards that fully take into consideration the nature of the data and the risks involved, such as for instance strict purpose limitation, access restrictions (including access only for staff having followed specialized training), keeping a record of access to the data, restrictions for onward transfers or additional security measures.
    • N/A
  • The frequency of the International Data Transfer (e.g. whether the Customer Personal Data is transferred on a one-off or continuous basis):
    • On a continuous basis.
  • Nature of the processing:
    • The Customer Personal Data will be processed and transferred as described in the Agreement.
  • Purpose(s) of the International Data Transfer and further Processing:
    • The Customer Personal Data will be transferred and further processed for the provision of the services as described in the Agreement.
  • The period for which the Customer Personal Data will be retained, or, if that is not possible, the criteria used to determine that period:
    • Customer Personal Data will be retained for as long as necessary taking into account the purpose of the Processing, and in compliance with applicable laws, including laws on the statute of limitations and Data Protection Law.
  • For International Data Transfer to (Sub)Processors, also specify subject matter, nature and duration of the Processing:
    • For the subject matter and nature of the Processing, reference is made to the Agreement and this DPA. The Processing will take place for the duration of the Agreement.

3. COMPETENT SUPERVISORY AUTHORITY

  • The competent authority for the Processing of Customer Personal Data relating to Data Subjects located in the EEA is the Supervisory Authority of Ireland.
  • The competent authority for the Processing of Customer Personal Data relating to Data Subjects located in the UK is the UK Information Commissioner.
  • The competent authority for the Processing of Customer Personal Data relating to Data Subjects located in Switzerland is the Swiss Federal Data Protection and Information Commissioner.

Annex II

ANNEX II

TECHNICAL AND ORGANIZATIONAL MEASURES INCLUDING TECHNICAL AND ORGANIZATIONAL MEASURES TO ENSURE THE SECURITY OF THE DATA

Eve will implement security safeguards designed to protect Customer Personal Data from unauthorized access, acquisition, or disclosure, destruction, alteration, accidental loss, misuse, or damage in accordance with the SOC 2, ISO 27001, NIST 800-53 or a substantially equivalent standard.

Customer data is stored by region in accordance with applicable Data Protection Laws.As of the Last Updated Date, all Customer data is stored in AWS US regions.

Customer data is encrypted at rest with AES-256 and in transit with TLS 1.2+.

Eve keeps data partitioned by account or by matter (matter-level partitioning is even more fine-grained) where appropriate, with logically isolated multi-tenant architecture, strict tenant segregation, enforced access controls, and row-level security.

Access to Customer Personal Data is limited to Eve personnel with a need to know, is role-based, and is subject to logging and periodic review. Multi-factor authentication is required for administrative access to production systems.

Eve personnel are subject to background screening where permitted by law, written confidentiality obligations, and security and privacy training at least annually.

Eve maintains a documented information security program, an incident response plan, and business continuity and disaster recovery procedures, each reviewed at least annually.

Eve conducts, or engages a qualified third party to conduct, penetration testing of the platform at least annually and remediates findings on a risk-prioritized basis.

Third-party model providers engaged as Subprocessors are configured such that Customer Personal Data is not retained after Processing and is not used to train Subprocessor large language models offered to the public generally.