This Data Protection Addendum (“DPA”) is incorporated to and forms part of the relevant agreement (the “Agreement”) between the Metropolis entity(ies) (collectively, “Metropolis”) and you (“Customer”) pursuant to which Agreement Metropolis provides the Services to Customer. Capitalized terms used but not defined in this DPA shall have the meaning as set forth in the Agreement. Metropolis and Customer may also be referred to hereunder as a “Party” or, collectively, the “Parties”.
1. DEFINITIONS
1.1 “Controller” means the entity which, alone or jointly with others, determines the purposes and means of Processing of Personal Data.
1.2 “Customer Personal Data” means Personal Data that is provided by Customer or otherwise collected via the Services on behalf of the Customer, and is not Services Data.
1.3 “Data Protection Laws” mean all laws applicable to the Processing of Customer Personal Data, including without limitation laws governing the collection, use, disclosure and other Processing of biometric data or information.
1.4 “Data Subject” means any individual about whom Customer Personal Data may be Processed under this DPA.
1.5 “Metropolis” means (i) Anyvision US LLC (d/b/a Metropolis Safety and Security Division) – if Licensee is established in the U.S, Latin or South America or Canada, (ii) KMP & Associates Limited (d/b/a Metropolis afety and Security Division) – if Licensee is established in Europe, the Middle East (not including Israel) or Africa, (iii) Anyvision Asia Pacific Pte. Ltd. (d/b/a Metropolis Safety and Security Division) – of Licensee is established in Asia Pacific or in the Middle East (alternatively), and (iv) Metropolis Advanced Technologies (IL) Ltd. (d/b/a Metropolis Safety and Security Division) – if none of the above applies or for Africa (alternatively) .
1.6 “Personal Data” means “personal data,” “personal information,” “personally identifiable information,” or an equivalent term under Data Protection Laws.
1.7 “Process” or “Processing” means any operation or set of operations performed on Customer Personal Data or on sets of Personal Data, whether by automated means, such as collection, recording, organization, structuring, storage, adaption or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction of Personal Data.
1.8 “Processor” means the entity which Processes Personal Data on behalf of the Controller.
1.9 “Services” means the services provided by Metropolis to Customer pursuant to the Agreement.
1.10 “Services Data” means data that relates to Metropolis’ relationship with Customer, including (i) contact information of individuals authorized by Customer to access Customer’s account; (ii) any data Metropolis may need to collect for the purpose of managing its relationship with Customer, identity verification, or as otherwise required by applicable laws and regulations; (iii) Service use data collected in connection with the provision of the Services, including without limitation data used to identify the source and destination of a communication, activity logs, and data used to optimize and maintain performance of the Services, and to investigate and prevent system abuse.
2. RELATIONSHIP BETWEEN THE PARTIES
The Parties acknowledge that for purposes of any Customer Personal Data processed by or on behalf of Metropolis when providing the Services pursuant to the Agreement, Customer is a Controller and Metropolis is a Processor (that will apply only for Services provided under Metropolis’s cloud based product such as Protect or in case Metropolis will Process Customer Personal Data when providing support Services for Metropolis’ on-prem products such as On-Watch, On-Access or On-Patrol). When using the Services under Metropolis’ on-prem products such as On-Watch, On-Access or On-Patrol; Customer is the Controller and the Processor. The Parties will Process Customer Personal Data in accordance with the Agreement and applicable Data Protection Laws.
3. CUSTOMER OBLIGATIONS
3.1 Customer represents and warrants that its collection of Customer Personal Data and disclosure to Metropolis complies with Data Protection Laws, and that Customer has provided all notices and obtained all consents required by Data Protection Laws to enable Metropolis to Process Customer Personal Data for the purposes set out in the Agreement, including Annex I to this DPA.
3.2 Customer shall, in its use of the Services, Process Personal Data in accordance with the requirements of any applicable laws, including but not limited to, Data Protection Laws, and the Illinois Biometric Information Privacy Act, and comply at all times with any and all obligations applicable to Customer. For the avoidance of doubt, Customer’s instructions for the Processing of Personal Data shall comply with any and all applicable laws. Customer shall have sole responsibility and liability for the means by which Customer acquired Personal Data. Without limitation, Customer shall comply with any and all transparency-related obligations (including, without limitation, displaying any and all relevant and required privacy notices or policies) and shall at all times have any and all required ongoing legal bases in order to collect, Process and transfer to Metropolis the Personal Data and to authorize the Processing by Metropolis of the Personal Data which is authorized in this DPA. Customer shall defend, hold harmless and indemnify Metropolis, its Affiliates and subsidiaries (including without limitation their directors, officers, agents, subcontractors and/or employees) from and against any liability of any kind related to any breach, violation or infringement by Customer and/or its authorized users of any applicable laws, including but not limited to, Data Protection Laws and/or this DPA and/or this Section.
4. INSTRUCTIONS.
4.1 Metropolis will Process Customer Personal Data only (i) in accordance with Customer’s instructions as documented in the Agreement, including Annex I to this DPA; and (ii) as needed to comply with applicable law, in which case Metropolis will inform Customer before Processing Customer Personal Data unless law prohibits such information on important grounds of public interest. Metropolis shall not be required to act on any Customer instruction that could (in Metropolis’ reasonable opinion) cause Metropolis to breach law. Metropolis will inform Customer if it believes that any Customer instructions regarding Customer Personal Data Processing would violate applicable Data Protection Law.
4.2 Metropolis will not be liable in the event of any claim brought by a third party, including, without limitation, a Data Subject, arising from any act or omission of Metropolis, to the extent that such is a result of Customer’s instructions. Metropolis expressly disclaims all responsibility and liability for the accuracy, copyright compliance, legality, or decency of any content provided by the Customer to the Services. The Customer acknowledges and agrees that it is the Customer’s sole responsibility to ensure that the use of the Services is permitted under the applicable laws and jurisdictions. The Customer shall take all necessary steps to ensure that its use of the Services complies with the relevant legal and regulatory requirements, including Data Protection Laws.
5. SECURITY
Metropolis will implement technical and organizational measures designed to protect Customer Personal Data against anticipated threats or hazards to its security, confidentiality, or integrity. Metropolis will require persons that Metropolis authorizes to Process Customer Personal Data to protect the confidentiality of the information. Annex II sets forth additional information regarding Metropolis’ technical and organizational security measures.
Metropolis may disclose and Process the Personal Data (a) as permitted hereunder (b) to the extent required by a court of competent jurisdiction, subpoena, governmental authority or other Supervisory Authority and/or otherwise as required by applicable laws or applicable Data Protection Laws, or (c) to legal counsel(s), data protection advisor(s), accountant(s), investors or potential acquirers.
6. SECURITY INCIDENTS
Metropolis will notify Customer without undue delay whenever Metropolis learns that there has been a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data that results in compromise of the privacy, security, integrity or availability of Customer Personal Data (“Security Incident”), unless prohibited by applicable law or otherwise instructed by law enforcement or a supervisory authority. Metropolis will make reasonable efforts to identify the cause of such Security Incident and take steps it deems necessary and reasonable in order to remediate such Security Incident and provide information about the Security Incident to Customer to enable Customer to comply with its obligations under Data Protection Laws, to the extent the Security Incident is within Metropolis’ reasonable control. The obligations herein shall not apply to incidents that are caused by Customer or Customer’s users or incidents not attributable to Metropolis or not under Metropolis’ control. In any event, Customer will be the party responsible for notifying supervisory authorities and/or concerned Data Subjects (where required by Data Protection Laws).
7. RETURN OR DISPOSAL
Following completion of the Services, Metropolis will delete all Customer Personal Data (including Customer Personal Data contained on back up media) within the retention period opted by the Customer under the Services which shall not exceed 90 days, unless applicable law requires or authorizes storage of Customer Personal Data by Metropolis. In any event, to the extent required or allowed by applicable law, Metropolis may retain one copy of the Personal Data for evidence purposes and/or for the establishment, exercise or defence of legal claims and/or to comply with applicable laws and regulations.
8. AUDITS; INQUIRIES
Upon Customer’s reasonable request (to be exercised no more than once a year, unless required more frequently by a supervisory authority) Metropolis will make available for Customer’s review copies of certifications or reports demonstrating Metropolis’ compliance with its obligations under this DPA. If the provision of reports or certifications is not reasonably sufficient under Data Protection Laws, Metropolis will allow an independent third party to be mutually agreed on by the Parties to conduct an audit or inspection of Metropolis’s data security infrastructure and procedures that is sufficient to demonstrate Metropolis’s compliance with its obligations under this DPA, provided that (i) Customer provides 60 days’ prior written notice of any such request for an audit and such inspection shall not be unreasonably disruptive to Metropolis’s business; (ii) such audit shall only be performed during business hours and occur no more than once per calendar year; and (iii) such audit shall be restricted to data relevant to Customer. Customer shall be responsible for the costs of any such audits or inspections, including without limitation reimbursing Metropolis for any time expended for on-site audits. All information provided will be Metropolis’ Confidential Information and may not be disclosed without Metropolis’ prior written consent, except as required by applicable law.
9. SUB-PROCESSORS
Customer authorizes Metropolis to transfer Customer Personal Data to sub-processors for purposes of providing the Services to Customer. Metropolis will maintain a list of the sub-processors and will provide this list to Customer upon request. Metropolis will provide Customer 3 business days’ prior notice when adding a sub-processor to this list and the opportunity to object to such addition on grounds relating to privacy and data protection. If Metropolis does not receive an objection within 3 business days of the notice, the sub-processor is deemed to be accepted by Customer. In the event Customer objects to a new sub-processor on the basis of reasonable data protection concerns, Metropolis will discuss such concerns in good faith with Customer to see whether they can be resolved. If the parties are unable to mutually agree to a resolution of such concerns, Metropolis or Customer may terminate the Agreement by providing written notice to the other Party. Any termination pursuant to this Section 9 will not affect Customer’s obligation to pay fees incurred prior to the termination. Customer will have no further claims against Metropolis due to the termination of the Agreement (including, without limitation, requesting refunds) and/or the DPA pursuant to this Section 9. Metropolis will enter into an agreement with such sub-processor that includes data protection terms similar to this DPA.
10. Metropolis ASSISTANCE.
At Customer’s reasonable request and expense and taking into account the nature of the Processing and information available to Metropolis, Metropolis will take reasonable steps: (i) to assist Customer with Customer’s obligation to respond to Data Subjects’ requests to exercise their rights under applicable law by taking appropriate technical and organizational measures; and (ii) in meeting Customer’s compliance obligations to establish and maintain records of Processing activities, and carry out data protection impact assessments and related consultations with supervisory authorities.
11. CALIFORNIA CONSUMER PRIVACY ACT (CCPA) PROVISIONS
11.1 Legal Compliance. Metropolis will provide the same level of privacy protection for Customer Personal Data of California residents as required of Customer under the CCPA. Metropolis will notify Customer in writing if Metropolis determines that it can no longer meet its obligations under the CCPA. Customer has the right, upon providing notice to Metropolis, to take reasonable and appropriate steps to stop and remediate unauthorized use of Customer Personal Data, including where Metropolis has notified Customer that it can no longer meet its CCPA obligations.
11.2 Restriction on Processing In no event may Metropolis: (a) disclose Customer Personal Data of California residents to a third party for monetary or other valuable consideration or disclose Customer Personal Data to a third party for cross-context behavioral advertising; (b) disclose Customer Personal Data of California residents to any third party for the commercial benefit of Metropolis or any third party; (c) retain, use, or disclose Customer Personal Data of California residents outside of Metropolis’ direct business relationship with Customer or for a commercial purpose other than the business purposes specified in the Agreement or as otherwise permitted by applicable laws; or (d) combine Customer Personal Data of California residents with personal information that Metropolis receives from, or on behalf of, other persons, or collects from its own interaction with the Data Subject, except as permitted under applicable laws. Metropolis certifies that it understands and will comply with the foregoing restrictions.
11.3 Notwithstanding the foregoing, Metropolis may use, disclose, or retain Customer Personal Data to: (i) transfer the Personal Data to other Metropolis’s entities (including, without limitation, affiliates and subsidiaries), service providers, third parties and vendors, in order to provide the Services to Customer; (ii) to comply with, or as allowed by, applicable laws; (iii) to defend legal claims or comply with a law enforcement investigation; (iv) to detect data security incidents, or protect against fraudulent or illegal activity; (v) collect and analyse anonymous Data; and (vi) as otherwise agreed, instructed or consented by the Customer. “Business purpose” includes the Processing activities that Metropolis will perform to provide Services (as described in the Agreement), this DPA and any other instruction from Customer, as otherwise permitted by applicable law, including, the CCPA and the applicable regulations, or as otherwise necessary to provide the Services to Customer.
12. DATA TRANSFERS
12.1 Restricted Transfers from the EEA. The EU Standard Contractual Clauses (Module 2 Controller to Processor) ((EU) 2021/914) available at https://eur-lex.europa.eu/eli/dec_impl/2021/914 (“EU SCCs”), and incorporated herein by reference, together with the attached Annexes I and II will apply as completed below to any transfer to Metropolis of Customer Personal Data from Customer in the European Economic Area (“EEA”). Notwithstanding the foregoing, the EU SCCs will not apply to the extent the transfer is covered by a decision adopted by a competent authority with jurisdiction over Customer declaring that a jurisdiction meets an adequate level of protection of Customer Personal Data (an “Adequacy Decision”). Signature to the Agreement will be considered a signature to the EU SCCs. The Parties agree that the EU SCCs will be completed as follows:
12.1.1 Optional Clause 7 is removed.
12.1.2 In Clause 9, the Parties agree that Option 2 will apply in accordance with Section 9 (Sub-Processors).
12.1.3 The optional language in Clause 11 is excluded.
12.1.4 In Clause 17, the EU SCCs will be governed by the laws of Ireland.
12.1.5 In Clause 18, any dispute arising from the EU SCCs will be resolved by the courts of Ireland.
12.1.6 In Annex IC, the data protection authority where Customer is located is the competent supervisory authority.
12.2 Restricted Transfers from Switzerland. . The EU SCCs, as modified in this section, will apply to any transfer to Metropolis of Customer Personal Data from Customer in Switzerland where the transfer is not otherwise subject to an Adequacy Decision:
12.2.1 The term “EU Member State” must not be interpreted in such a way as to exclude Data Subjects in Switzerland from the possibility for suing their rights in their place of habitual residence (Switzerland) in accordance with Clause 18(c).
12.2.2 References in the EU SCCs to the GDPR are to be understood as references to the Federal Act on Data Protection (FADP).
12.2.3 In Clause 17, the EU SCCs will be governed by the laws of Switzerland.
12.2.4 In Annex IC, the Swiss Federal Data Protection and Information Commissioner is the competent supervisory authority.
12.3 Restricted Transfers from the United Kingdom. . Where Customer Personal Data is transferred to Metropolis from Customer in the UK and the transfer is not otherwise subject to an Adequacy Decision, the Parties agree:
12.3.1 The provisions of the UK International Data Transfer Addendum to the EU Commission Standard Contractual Clauses, Version B1.0, in force from March 21, 2022, available at https://ico.org.uk/media/for-organisations/documents/4019539/international-data-transfer-addendum.pdf (“UK Addendum”) are herein incorporated by reference and shall apply in full;
12.3.2 In Table 1 of the UK Addendum, the names of the Parties, their roles and their details shall be set out in the attached Annex 1;
12.3.3 In Tables 2 and 3 of the UK Addendum, Module 2 of the EU SCCs incorporated into this DPA by reference, including the information set out in the attached Annexes, shall apply; and
12.3.4 In Table 4 of the UK Addendum, either Party may end the UK Addendum.
12.4 Restricted Transfers from the Abu Dhabi Global Market (“ADGM”). . This Section 12.4 applies solely to transfers of Customer Personal Data by Customer in ADGM to Metropolis or an authorized sub-processor (i) located outside ADGM and (ii) not subject to an Adequacy Decision. Such transfers will be governed by the ADGM Standard Contractual Clauses (located at https://assets.adgm.com/download/assets/ADGM—DPR-2021-Data-Transfer-SCCs.docx/bda6e044595911ef906636e29b0f3a63 and incorporated herein by reference).
12.5 Restricted Transfers from the Dubai International Financial Center (“DIFC. This Section 12.5 applies solely to transfers of Customer Personal Data by Customer in DIFC to Metropolis or an authorized sub-processor (i) located outside DIFC and (ii) not subject to an Adequacy Decision. Such transfers will be governed by the DIFC Standard Contractual Clauses (located at https://www.difc.com/business/registrars-and-commissioners/commissioner-of-data-protection/data-export-and-sharing and incorporated herein by reference).
12.6 Restricted Transfers from the Qatar Financial Center (“QFC”). . This Section 12.6 applies solely to transfers of Customer Personal Data by Customer in QFC to Metropolis or an authorized sub-processor (i) located outside QFC and (ii) not subject to an Adequacy Decision. Such transfers will be governed by the QFC Standard Contractual Clauses (located at https://www.qfc.qa/-/media/project/qfc/qfcwebsite/documentfiles/resource-center/data-protection/data-transfers/qfc-standard-contractual-clauses.docx and incorporated herein by reference).
13. ANALYTICS DATA
Customer acknowledges and agrees that Metropolis may create and derive from Processing related to the Services anonymized and/or aggregated data that does not identify or relate to Customer or any Data Subject (“Analytics Data”) and use such Analytics Data for Metropolis’ own business purposes.
14. SERVICES DATA.
The Parties acknowledge and agree that Metropolis is an independent Controller with respect to Services Data. Metropolis will process Services Data in accordance with the Metropolis’ privacy policy set forth at https://Metropolis.com/privacy.
15. LIABILITY.
Each Party’s liability towards the other Party under or in connection with this DPA will be limited in accordance with the provisions of the Agreement. Customer acknowledges that Metropolis is reliant on Customer for direction as to the extent to which Metropolis is entitled to Process Customer Personal Data on behalf of Customer in performance of the Services. Consequently, Metropolis will not be liable under the Agreement for any claim brought by a Data Subject arising from (a) any action or omission by Metropolis in compliance with Customer’s instructions or (b) from Customer’s failure to comply with its obligations under the Data Protection Laws.
16. AUTHORIZED AFFILIATES
The Parties acknowledge and agree that, by executing the DPA, Customer enters into the DPA on behalf of itself and, as applicable, in the name and on behalf of its affiliates, thereby establishing a separate DPA between Metropolis. Each affiliate agrees to be bound by the obligations under this DPA. All access to and use of the Services by affiliates must comply with the terms and conditions of the Agreement and this DPA and any violation of the terms and conditions therein by an affiliate shall be deemed a violation by Customer. Customer shall remain responsible for coordinating all communication with Metropolis under the Agreement and this DPA and shall be entitled to make and receive any communication in relation to this DPA on behalf of its affiliates.
17. MODIFICATIONS
If required by applicable law, Metropolis may modify this DPA with respect to such requirements upon written notice to Customer to the email address(es) provided via the Notice Form.
18. CONFLICTS; ENFORCEABILITY
If any provision of this DPA is held to be invalid or unenforceable by any court of competent jurisdiction, such holding will not invalidate or render unenforceable any other provision of this DPA or any other contract between Customer and Metropolis. This DPA supplements the Agreement. This DPA shall be attached as an Annex to the Agreement, and it will control in the event of any inconsistency between the Agreement and this DPA. Any other provisions of or obligations under the Agreement that are otherwise unaffected by this DPA will remain in full force and effect. This DPA shall only become effective at the effective date of the Agreement. If this DPA, or any actions to be taken or contemplated to be taken in performance of this DPA, do not or would not satisfy either Party’s obligations under the laws applicable to each Party, the Parties will negotiate in good faith upon an appropriate amendment to this DPA.
ANNEX I
LIST OF PARTIES AND DESCRIPTION OF TRANSFER
A. LIST OF PARTIES
Data exporter(s):
| Name | Customer name, as specified in the Agreement |
| Address | Customer address, as specified in the Agreement |
| Contact person’s name, position, contact details | Customer contact information, as specified in the Agreement |
| Signature and date | As indicated via signature or execution of the Agreement |
| Role (controller/processor) | Controller |
Data exporter(s):
| Name | Metropolis entity as specified in the Agreement |
| Address | Metropolis entity address, as specified in the Agreement |
| Contact person’s name, position, contact details | Dalila Barnatan, Deputy General Counsel, [email protected] |
| Signature and date | As indicated via signature to or other form of execution of the Agreement by Customer |
| Role (controller/processor) | Processor |
B. DESCRIPTION OF TRANSFER
| Categories of data subjects whose personal data is transferred | Customer may submit Personal Data to the Services, the extent of which is determined and controlled by Customer in its sole discretion, and which may include, but is not limited to Personal Data relating to the following categories of Data Subjects: (1) Customer’s customers, visitors, clients and/or any other natural person that appears in the videos, recordings, images and watch lists shared by Customer with Metropolis during customer support activities; and (2) Employees, agents, advisors, service providers, freelancers of Customer (who are natural persons). |
| Categories of personal data transferred | Depending on the type of product or Service provided to Customer and the relevant configuration, Personal Data may include Customer’s provided videos, recordings, and images; Customer’s watch list information (to the extent that it includes Personal Data); and biometric data derived therefrom. |
| The frequency of the transfer | Continuous basis. |
| Nature and purpose of the processing | Performing the Agreement, this DPA and/or other contracts executed by the Parties, including, providing the Services to Customer (including, the biometric processing activities) and providing support and technical maintenance, if set forth in the Agreement. |
| Duration of processing | Personal Data will be retained for the period required to perform the Services under the Agreement unless a longer period is permitted or required by applicable law. |
| For transfers to (sub-) processors, also specify subject matter, nature, and duration of the processing | See description above. |