{"id":2215,"date":"2024-05-09T13:58:04","date_gmt":"2024-05-09T13:58:04","guid":{"rendered":"https:\/\/www.bloomreach.com\/legal\/dpa-all-products-1-march-2022"},"modified":"2024-09-12T12:50:34","modified_gmt":"2024-09-12T12:50:34","slug":"dpa-all-products-1-march-2022","status":"publish","type":"legal","link":"https:\/\/www.bloomreach.com\/en\/legal\/dpa-all-products-1-march-2022","title":{"rendered":"All Data Processing Addendum"},"content":{"rendered":"<section>\n<div class=\"container\">\n<div class=\"row\">\n<div class=\"col-lg-12\">\n                <!--content start--><\/p>\n<p dir=\"ltr\" style=\"line-height:1.2;margin-right: 0.45pt;text-align: center;margin-top:0pt;margin-bottom:6pt;\"><span id=\"docs-internal-guid-71e8a0e3-7fff-d559-56f7-44ccfbfde900\"><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">DATA PROCESSING ADDENDUM<\/span><\/span><\/p>\n<p>(Effective: 1 March 2022 and 7 December 2022)<\/p>\n<p>For other versions of Bloomreach\u2019s Data Processing Agreement, click <a href=\"https:\/\/www.bloomreach.com\/en\/legal\/dpa-all\">here<\/a>.<\/p>\n<p>&nbsp;<\/p>\n<p dir=\"ltr\" style=\"line-height:1.2;text-align: justify;margin-top:0pt;margin-bottom:6pt;\"><span id=\"docs-internal-guid-71e8a0e3-7fff-d559-56f7-44ccfbfde900\"><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">This Data Processing Addendum (&ldquo;<\/span><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">DPA<\/span><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">&rdquo;) is an addendum to and forms part of the Agreement between Bloomreach (&quot;<\/span><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">Bloomreach<\/span><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">&quot; and &quot;<\/span><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">data importer<\/span><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">&quot;) and party identified as the Customer in the Agreement (&quot;<\/span><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">Customer<\/span><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">&quot; or &quot;<\/span><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">data exporter<\/span><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">&quot;). This DPA sets out the terms that apply to the parties when Processing Personal Data in connection with the provision of the Services.&nbsp;&nbsp;<\/span><\/span><\/p>\n<p dir=\"ltr\" style=\"line-height:1.2;text-align: justify;margin-top:0pt;margin-bottom:6pt;\"><span id=\"docs-internal-guid-71e8a0e3-7fff-d559-56f7-44ccfbfde900\"><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">For the avoidance of doubt, the Bloomreach Entity that is the party to the Agreement, shall be the same party entering into this DPA.&nbsp;<\/span><\/span><\/p>\n<p>&nbsp;<\/p>\n<p dir=\"ltr\" style=\"line-height:1.2;text-align: justify;margin-top:0pt;margin-bottom:6pt;\"><span id=\"docs-internal-guid-71e8a0e3-7fff-d559-56f7-44ccfbfde900\"><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">DEFINITIONS<\/span><\/span><\/p>\n<p dir=\"ltr\" style=\"line-height:1.2;text-align: justify;margin-top:0pt;margin-bottom:6pt;\"><span id=\"docs-internal-guid-71e8a0e3-7fff-d559-56f7-44ccfbfde900\"><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">For the purposes of this DPA, capitalized terms not otherwise defined shall have the meaning given to them in the Agreement.&nbsp;<\/span><\/span><\/p>\n<p dir=\"ltr\" style=\"line-height:1.2;text-align: justify;margin-top:0pt;margin-bottom:6pt;\"><span id=\"docs-internal-guid-71e8a0e3-7fff-d559-56f7-44ccfbfde900\"><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">&ldquo;<\/span><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">Agreement<\/span><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">&rdquo; means either (i) the Master Subscription Agreement, together with applicable Appendices and Sales Orders; or (ii) any other written or electronic agreement incorporating this DPA, governing the Customer&#39;s access and use of the Services.&nbsp;<\/span><\/span><\/p>\n<p dir=\"ltr\" style=\"line-height:1.2;text-align: justify;margin-top:0pt;margin-bottom:6pt;\"><span id=\"docs-internal-guid-71e8a0e3-7fff-d559-56f7-44ccfbfde900\"><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">&quot;<\/span><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">Bloomreach<\/span><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">&quot; means the Bloomreach Entity that is a party to the Agreement.<\/span><\/span><\/p>\n<p dir=\"ltr\" style=\"line-height:1.2;text-align: justify;margin-top:0pt;margin-bottom:6pt;\"><span id=\"docs-internal-guid-71e8a0e3-7fff-d559-56f7-44ccfbfde900\"><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">&quot;<\/span><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">Bloomreach Entity<\/span><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">&quot; means Bloomreach, Inc., Bloomreach B.V. or any other Affiliate of Bloomreach Inc.&nbsp;&nbsp;<\/span><\/span><\/p>\n<p dir=\"ltr\" style=\"line-height:1.2;margin-left: -18pt;text-indent: 18pt;text-align: justify;margin-top:0pt;margin-bottom:6pt;\"><span id=\"docs-internal-guid-71e8a0e3-7fff-d559-56f7-44ccfbfde900\"><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">&ldquo;<\/span><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">Affiliate(s)<\/span><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">&rdquo; means any entity controlling, controlled by, or under common control of a Party.<\/span><\/span><\/p>\n<p dir=\"ltr\" style=\"line-height:1.2;margin-left: -0.25pt;text-indent: 0.25pt;text-align: justify;margin-top:0pt;margin-bottom:6pt;\"><span id=\"docs-internal-guid-71e8a0e3-7fff-d559-56f7-44ccfbfde900\"><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">&ldquo;<\/span><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">CCPA<\/span><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">&rdquo; means the California Consumer Privacy Act, California Civil Code &sect;&sect;1798.100 et seq., including any amendments and implementing regulations that become effective on or after the effective date of this DPA.&nbsp;<\/span><\/span><\/p>\n<p dir=\"ltr\" style=\"line-height:1.2;margin-left: -0.25pt;text-indent: 0.25pt;text-align: justify;margin-top:0pt;margin-bottom:6pt;\"><span id=\"docs-internal-guid-71e8a0e3-7fff-d559-56f7-44ccfbfde900\"><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">&ldquo;<\/span><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">Data Breach<\/span><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">&rdquo; means a breach of security of the Services leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data transmitted, stored or otherwise Processed by Bloomreach under this DPA.&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<\/span><\/span><\/p>\n<p dir=\"ltr\" style=\"line-height:1.2;margin-left: -0.25pt;text-indent: 0.25pt;text-align: justify;margin-top:0pt;margin-bottom:6pt;\"><span id=\"docs-internal-guid-71e8a0e3-7fff-d559-56f7-44ccfbfde900\"><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">&ldquo;<\/span><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">Data Protection Legislation<\/span><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">&rdquo; means, as applicable to a party and its Processing of Personal Data: (i) the CCPA and any national data protection laws made under the CCPA, and (ii) EU\/ UK Data Protection Law.&nbsp;<\/span><\/span><\/p>\n<p dir=\"ltr\" style=\"line-height:1.2;margin-left: -0.25pt;text-indent: 0.25pt;text-align: justify;margin-top:0pt;margin-bottom:6pt;\"><span id=\"docs-internal-guid-71e8a0e3-7fff-d559-56f7-44ccfbfde900\"><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">&quot;<\/span><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">EU\/UK Data Protection Law<\/span><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">&quot; means: (i) Regulation 2016\/679 of the European Parliament and of the Council on the protection of natural persons with regard to the Processing of Personal Data and on the free movement of such data&nbsp; (the &quot;<\/span><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">GDPR<\/span><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">&quot;); (ii) the GDPR as saved into United Kingdom law by virtue of section 3 of the United Kingdom&#39;s European Union (Withdrawal) Act 2018 (the &quot;<\/span><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">UK GDPR<\/span><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">&quot;); (iii) the EU e-Privacy Directive (Directive 2002\/58\/EC); (iv) the Swiss Federal Act on Data Protection 1992 (&quot;<\/span><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">Swiss DPA<\/span><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">&quot;); and (iv) any and all applicable national data protection laws made under, pursuant to or that apply in conjunction with any of (i), (ii) (iii) or (iv); in each case as may be amended or superseded from time to time.<\/span><\/span><\/p>\n<p dir=\"ltr\" style=\"line-height:1.2;margin-left: -0.25pt;text-indent: 0.25pt;text-align: justify;margin-top:0pt;margin-bottom:6pt;\"><span id=\"docs-internal-guid-71e8a0e3-7fff-d559-56f7-44ccfbfde900\"><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">&ldquo;<\/span><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">Personal Data<\/span><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">&rdquo; means any information that&nbsp; (i) is protected as &quot;personal data&quot;, &quot;personal information&quot; or &quot;personally identifiable information&quot; under Data Protection Legislation; and (ii) is Processed by Bloomreach on behalf of Customer in the course of providing the Services,&nbsp; as more particularly described in Annex 1 (A) of this DPA.&nbsp;<\/span><\/span><\/p>\n<p dir=\"ltr\" style=\"line-height:1.2;text-align: justify;margin-top:0pt;margin-bottom:6pt;\"><span id=\"docs-internal-guid-71e8a0e3-7fff-d559-56f7-44ccfbfde900\"><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">&quot;<\/span><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">Restricted Transfer<\/span><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">&quot; means: (i) where the GDPR applies, a transfer of Personal Data from the European Economic Area to a country outside of the European Economic Area which is not subject to an adequacy determination by the European Commission; (ii) where the UK GDPR applies, a transfer of Personal Data from the United Kingdom to any other country which is not subject based on adequacy regulations pursuant to Section 17A of the United Kingdom Data Protection Act 2018; and (iii) where the Swiss DPA applies, a transfer of Personal Data from Switzerland to any other country which is not determined to provide adequate protection for personal data by the Federal Data Protection and Information Commission or Federal Council (as applicable).<\/span><\/span><\/p>\n<p dir=\"ltr\" style=\"line-height:1.2;text-align: justify;margin-top:0pt;margin-bottom:6pt;\"><span id=\"docs-internal-guid-71e8a0e3-7fff-d559-56f7-44ccfbfde900\"><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">&ldquo;Sub-processor&rdquo; <\/span><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">means any third party engaged by Bloomreach to assist in fulfilling its obligations with respect to providing the Services and that Processes Personal Data as Processor.&nbsp;<\/span><\/span><\/p>\n<p dir=\"ltr\" style=\"line-height:1.2;margin-left: -0.25pt;text-align: justify;margin-top:0pt;margin-bottom:6pt;\"><span id=\"docs-internal-guid-71e8a0e3-7fff-d559-56f7-44ccfbfde900\"><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">&ldquo;Services&rdquo; <\/span><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">means the services provided by Bloomreach to the Customer pursuant to and as more particularly described in the Agreement.<\/span><\/span><\/p>\n<p dir=\"ltr\" style=\"line-height:1.2;margin-left: -0.25pt;text-align: justify;margin-top:0pt;margin-bottom:6pt;\"><span id=\"docs-internal-guid-71e8a0e3-7fff-d559-56f7-44ccfbfde900\"><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">&quot;Standard Contractual Clauses&quot; <\/span><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">means: (i) the standard contractual clauses annexed to the European Commission&#39;s Implementing Decision 2021\/914 of 4 June 2021 (the &quot;<\/span><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">EU SCCs<\/span><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">&quot;) ; and (ii) where the UK GDPR applies, standard data protection clauses adopted pursuant to Article 46(2)(c) or (d) of the UK GDPR (&quot;<\/span><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">UK SCCs<\/span><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">&quot;), as applicable in accordance with Section 6 (Data Transfers).<\/span><\/span><\/p>\n<p dir=\"ltr\" style=\"line-height:1.2;margin-left: -0.25pt;text-align: justify;margin-top:0pt;margin-bottom:6pt;\"><span id=\"docs-internal-guid-71e8a0e3-7fff-d559-56f7-44ccfbfde900\"><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">The terms &quot;Controller&quot;, &quot;Processor&quot;, &quot;Process&quot;, &quot;Processing&quot; and &quot;Data Subject&quot; shall have the same meanings given to them under the GDPR, and the terms &quot;business&quot;, &quot;service provider&quot; and &quot;sale&quot; have the same meaning given to it under the CCPA. <\/span><\/span><\/p>\n<div>&nbsp;<\/div>\n<p>                <!-- ol --><\/p>\n<p>                <strong>1. BLOOMREACH OBLIGATIONS<\/strong><\/p>\n<p>                1.1 Roles. For the purposes of EU\/UK Data Protection Law,  Customer is the Controller or Processor of Personal Data and Bloomreach shall Process Personal Data as a Processor; and for the purposes of the CCPA (where applicable), Customer is the &#8220;business&#8221; and Bloomreach is the &#8220;service provider&#8221;.<\/p>\n<p>                1.2 Permitted Purposes. Bloomreach shall Process Personal Data only for the purposes described in Annex 1. or otherwise agreed between the Parties and in accordance with the Customer&#8217;s documented lawful instructions (&#8220;Permitted Purposes&#8221;), except where otherwise required by law(s) that are not incompatible with applicable Data Protection Legislation.  In no event will Bloomreach Process Personal Data for its own purposes or those of a third party. In particular and to the extent the CCPA is applicable, Customer&#8217;s transfer of Personal Data to Bloomreach is not a sale, and Bloomreach provides no monetary or other valuable consideration to Customer in exchange for Personal Data. To the extent required by Data Protection Legislation, this Section 1.2 constitutes the certification from Bloomreach to the Processing instructions herein. Bloomreach acts on behalf of and on the instructions of the Customer in carrying out the Permitted Purposes.  <\/p>\n<p>                1.3 Processing Instructions. The Agreement, including this DPA, along with the Customer&#8217;s configuration of any settings or options in the Services, constitute Customer&#8217;s complete and final instructions to Bloomreach regarding the Processing of Personal Data, including for the purposes of the Standard Contractual Clauses. Any additional or alternate instructions must be consistent with the terms of the  Agreement.  Bloomreach: (i) shall immediately inform the Customer if it becomes aware that Customer&#8217;s Processing instructions infringe Data Protection Legislation (but without obligation to actively monitor Customer&#8217;s or, where applicable its Controller&#8217;s,  compliance with Data Protection Legislation); and (ii)  in such circumstances, Bloomreach may, without liability, temporarily cease all Processing of the affected Personal Data (other than securely storing such data) and\/or suspend access to the Customer\u2019s account. If parties do not agree on a resolution to the issue in question and the costs thereof, Customer may as its sole and exclusive remedy, terminate the Agreement (including this DPA) with respect to the affected Processing. Customer will have no further claims against Bloomreach (including, without limitation, requesting refunds for the Services) pursuant to the termination of the Agreement as described in this Section.  <\/p>\n<p>                1.4 Security Measures. Bloomreach shall implement and maintain reasonable and appropriate technical and organizational measures designed to protect Personal Data from Data Breaches and to preserve security and confidentiality of Personal Data, in accordance with the measures identified in Annex 3 of this DPA (&#8220;Security Measures&#8221;). The Customer acknowledges that the Security Measures are subject to technical progress and development and accordingly, Bloomreach may update or modify the Security Measures from time to time provided  that such updates and modifications do not degrade or diminish the overall security of the Services.<\/p>\n<p>                1.5 Access and Confidentiality. Bloomreach shall ensure that any personnel tasked with  the Processing the Personal Data shall be subject to appropriate obligations of confidentiality (whether a contractual or statutory duty), have received appropriate training, and that they Process Personal Data only for the Permitted Purposes.<\/p>\n<p>                1.6 Data Returns and Deletion. Upon termination or expiration of the Agreement, Bloomreach shall (at Customer&#8217;s election) delete or return to Customer all Personal Data (including copies) in its possession or control in accordance with the Agreement. The parties agree that this requirement shall not apply to the extent Bloomreach is required by applicable law to retain some or all of the Personal Data, or to Personal Data archived on back-up systems, which Personal Data Bloomreach shall securely isolate and protect from any further Processing. Bloomreach shall delete such retained data without undue delay when technically feasible and\/or allowed by the applicable law. The parties agree that the certification of deletion of Personal Data described in Clause 8.5 and 16.(d) of EU SCCs shall be provided by Bloomreach to Customer only upon Customer&#8217;s written request.<\/p>\n<p>\n                <strong>2. Audit  Rights<\/strong><\/p>\n<p>                2.1 Audit Reports. Upon request, Bloomreach shall supply (on a confidential basis) copies of any certifications, audit report summaries and\/or other relevant documentation it holds and which Bloomreach generally makes available to its customers. In addition, Bloomreach shall respond to all reasonable requests for information made by Customer that are necessary to confirm Bloomreach&#8217;s compliance with this DPA, including responses to information security, due diligence and audit questionnaires, by making additional information available regarding its security program upon Customer&#8217;s written request, provided that Customer shall not exercise this right more than once per year.<\/p>\n<p>                2.2 Audit. Whilst it is the parties intention to ordinarily rely on the  audit measures described in Section 2.1 (above) to verify Bloomreach&#8217;s compliance with this DPA (including the Standard Contractual Clauses), following a confirmed Data Breach or where a data protection authority requires it, Bloomreach shall allow the Customer (or subject to complying with Section 2.3, a third party licensed auditor) to carry out the on-site or remote audit of Bloomreach&#8217;s electronic data files, systems and documentation relating to the Processing of Personal Data, provided that: (i) Data Protection Legislation obliges Bloomreach to allow for such audit (ii) Bloomreach is notified of the audit via a written notice at least 30 (thirty) days in advance; (iii) the audit shall be conducted at Customer&#8217;s expense; (iv) the parties shall mutually agree upon the scope, timing and duration of the audit; and (v) the audit shall not take place more than once a calendar year and shall not unreasonably impact Bloomreach&#8217;s regular operations.<\/p>\n<p>                2.3 Audit by a third party. Customer may exercise its audit rights under Section 2.2 through the engagement of a third independent party that is an external licensed auditor, provided that Customer provides Bloomreach with reasonable prior written notice and the opportunity to object in accordance with this Section 2.3. Bloomreach may object to such an auditor conducting the audit if the auditor is, in Bloomreach\u2019s reasonable opinion, not suitably qualified or independent, a competitor of Bloomreach, or otherwise manifestly unsuitable. Any such objection will require the Customer to appoint another auditor.<\/p>\n<p>\n                <strong>3. CUSTOMER\u2019S OBLIGATIONS<\/strong><\/p>\n<p>                3.1 Customer\u2019s Processing of Personal Data. Customer shall, in its use of the Services and provision of its Processing instructions, Process Personal Data in accordance with Data Protection Legislation (including where the Customer is a Processor, by ensuring the ultimate Controller does so). Customer shall have sole responsibility for the accuracy, quality, and legality of Personal Data and the means by which Customer acquired Personal Data.  Where Customer acts as a Processor on behalf of a third party Controller (or other intermediary to the ultimate Controller), Customer warrants that its Processing instructions, including its authorizations to Bloomreach for the appointment of Sub-processor in accordance with this DPA, have been authorized by the relevant Controller. The Customer shall be solely responsible for forwarding any notifications received by Bloomreach to the relevant Controller where appropriate.<\/p>\n<p>                3.2 Customer\u2019s Compliance. Customer agrees that (i) it shall comply with its obligations as a Controller under Data Protection Legislation in respect of its Processing of Personal Data and any Processing instructions it issues to Bloomreach; (ii) it has provided notice and obtained (or shall obtain) all consents or any other necessary authorizations (as applicable) under Data Protection Legislation for Bloomreach to Process Personal Data for the Permitted Purposes, (iii) it has fulfilled (or shall fulfill) all registration or notification obligations to which Customer is subject to under the Data Protection Legislation and (iv) it is responsible for its own Processing of Personal Data including  integrity, security, maintenance and appropriate protection of Personal Data that are under Customer\u2019s control.<\/p>\n<p>                3.3 Technical and organizational measures. Without prejudice to Bloomreach&#8217;s obligations under Section1.4 (Security Measures), Customer is responsible for its secure use of the Services, including securing its account authentication credentials, protecting the security of Personal Data when in transit to and from the Services and taking any appropriate technical, organizational and security measures to securely encrypt or backup any Personal Data uploaded to the Services. Customer is also responsible for the use of the Services by any of its employees, any person Customer authorizes to access or use the Services, and any person who gains access to its Personal Data or the Services as a result of its failure to use reasonable security precautions, even if such use was not authorized by Customer. Customer agrees to immediately notify Bloomreach of any unauthorized use of Services or Customer\u2019s Account or of any other breach of security involving the Services upon becoming aware.<\/p>\n<p>                3.4 Use of Cookies. Where the Services employ the use of cookies and\/or similar tracking technologies (&#8220;Cookies&#8221;), Customer shall maintain appropriate notice and consent mechanisms as required by Data Protection Legislation and industry best practice (or as otherwise reasonably requested by Bloomreach) to enable Bloomreach to lawfully deploy Cookies on, and lawfully collect data from, the devices of Data Subjects for the purposes of providing the Services. Bloomreach upon request shall provide Customer with all information reasonably required by the Customer (including details about the Cookies) to enable Customer to provide such notice. The Customer shall promptly notify Bloomreach if it is unable to comply with its obligations under this Section 3.4.<\/p>\n<p>\n                <strong>4. COOPERATION<\/strong>  <\/p>\n<p>                4.1 Data Subject Rights. To the extent that Customer is unable to independently access the relevant Personal Data within the Services, Bloomreach shall (at Customer&#8217;s expense), taking into account the nature of the Processing, provide reasonable assistance (including by appropriate technical and organizational measures, in so far as this is possible), to enable Customer to: (i) respond to any requests from a data subject seeking to exercise any of its rights under Data Protection Legislation (including its right of access, correction, objection, erasure and data portability, as applicable); and (ii) any other correspondence, enquiry or complaint received from a data subject, regulator or other third party in connection with the processing of the Personal Data (collectively &#8220;Correspondence&#8221;).  In the event that any Correspondence from a Data Subject is made directly to Bloomreach, it shall where the Customer is identified or identifiable from the Correspondence, promptly notify Customer (who, where Customer is a Processor, shall in turn be responsible for informing the ultimate Controller) and shall not, unless legally compelled to do so, respond directly, except that Customer authorizes Bloomreach to redirect the Data Subject as necessary to allow Customer to respond as appropriate. Any assistance provided under this Section 4.1 shall be relevant to Services that support the Processing of Personal Data, commercially reasonable and proportionate to the objective of the exercise with which Bloomreach is requested to assist.      <\/p>\n<p>                4.2 Data Protection Impact Assessment. To the extent required by Data Protection Legislation, Bloomreach shall (taking into account the nature of the Processing and the information available to Bloomreach) provide all reasonably requested information regarding the Services to enable Customer to carry out data protection impact assessments or prior consultations with data protection authorities as required by Data Protection Legislation. Bloomreach shall comply with the foregoing by: (i) complying with Section 2 (Audit Rights); (ii) providing the information contained in the Agreement, including this DPA; and (iii) if the foregoing sub-sections (i) and (ii) are insufficient for Customer to comply with such obligations, upon request, providing additional reasonable assistance at Customer&#8217;s expense.<\/p>\n<p>                4.3 Data Breaches<\/p>\n<div style=\"padding-left: 20px;\">\n                    4.3.1 Data Breach Notification. Upon becoming aware of a Data Breach, Bloomreach shall notify the Customer (who, where Customer is a Processor, shall in turn be responsible for informing the ultimate Controller(s)) without undue delay and shall provide such timely information and cooperation as Customer may reasonably require in order for Customer (or where Customer is a Processor, its Controller) to fulfil its data breach reporting obligations under Data Protection Legislation. Where, and in so far as, it is not possible to provide all the details at the same time, the information may be provided in phases, without undue delay. Bloomreach shall further take all such measures and actions as are necessary to remedy or mitigate the effects of the Data Breach and shall keep Customer informed of all developments in connection with the Data Breach. Customer agrees that Bloomreach&#8217;s obligation to notify the Data Breach is not an acknowledgement by Bloomreach of any fault or liability of Bloomreach with respect to such Data Breach. If a Data Breach is caused or materially contributed to by Customer, Bloomreach will reasonably cooperate in the investigation of the Data Breach subject to Customer&#8217;s obligation to compensate Bloomreach for its reasonable costs.<\/p>\n<p>                    4.3.2 Liability for Data Breaches. Bloomreach&#8217;s liability for a Data Breach toward Customer and any third party is subject to the following limitations: (a) the Data Breach is a result of a breach of Bloomreach&#8217;s information security obligations under this DPA; and (b) the Data Breach is not caused by: (i) acts or omissions of Customer, or any person acting on behalf of or jointly with Customer, including any Authorized Users (collectively &#8220;Customer Representatives&#8221;); or (ii) Customer Representatives&#8217; instructions to Bloomreach.<\/p>\n<p>\n                <\/div>\n<p>                <strong>5. SUB-PROCESSING<\/strong><\/p>\n<p>                5.1 Authorized Sub-processors. Customer provides a general authorization for Bloomreach to engage Sub-processors to Process Personal Data on Customer&#8217;s behalf, including the Sub-processors listed in Annex 2 (&#8220;Sub-processor List&#8221;). Updated list of Sub-processors will always be available at https:\/\/www.bloomreach.com\/en\/legal\/subprocessors  and Bloomreach will be considered to have provided a notification on adding a new Subprocessor to Customer by publishing the Sub-processor\u00b4s name on the said link. Customer may also opt to receive notifications of new Sub-processors by emailing subnotification@bloomreach.com with the subject &#8220;Subscribe&#8221; and if a Customer contact subscribes, Bloomreach shall provide the subscriber with notification of new Sub-processor&#8217;s. The Customer will have the right to object to addition of a new Sub-processor in accordance with Section 5.2 below. Bloomreach shall  impose substantially the same data protection terms on any Sub-processor it appoints as contained in this DPA (including data transfer provisions, where applicable) and shall remain responsible for any acts or omissions of Sub-processor\u2019s to the extent they cause Bloomreach to breach any of its obligations under this DPA.  <\/p>\n<p>                5.2 Objections to Sub-processors. Bloomreach shall notify Customer if it adds or removes Sub-processors  using the mechanism set out in Section 5.1 above. The Customer may object in writing to the appointment of such a new Sub-processor on reasonable grounds relating to data protection by notifying Bloomreach promptly in writing within 10 calendar days of receipt of Bloomreach&#8217;s notice. Such notice shall explain the reasonable grounds for the objections. In such an event, the parties shall discuss Customer\u00b4s concerns in good faith with a view to achieving commercially reasonable resolution.<\/p>\n<p>\n                <strong>6. DATA TRANSFERS<\/strong><\/p>\n<p>                6.1 International data transfers.  Personal Data that Bloomreach Processes under the Agreement may be Processed in any country in which Bloomreach and its Sub-processors maintain facilities to perform the Services, as further detailed in the Sub-processor List. Bloomreach shall not participate in (nor permit any Sub-processors to participate in) any Restricted Transfers of Personal Data unless the Restricted Transfer is made in compliance with EU\/ UK Data Protection Law and this DPA.<\/p>\n<p>                6.2 Application of Standard Contractual Clauses. <\/p>\n<div style=\"padding-left: 20px;\">\n                    6.2.1 The Parties agree that when and to the extent the transfer of Personal Data from Customer to Bloomreach is a Restricted Transfer and EU\/UK Data protection Law requires that appropriate safeguards are put in place, such  transfer shall be governed by the Standard Contractual Clauses, which shall be incorporated by reference into and form an integral part of this DPA as follows.<\/p>\n<p>                    6.2.2 In relation to transfers of Personal Data protected by GDPR the EU SCCs will apply with following modifications:<\/p>\n<div style=\"padding-left: 20px;\">\n                        6.2.2.1 where Customer is a Controller of Personal Data, Module Two (Controller to Processor Clauses) will apply and where Customer is a Processor acting on behalf of third party Controllers, Module 3 (Processor to Processor Clauses) will apply;<\/p>\n<p>                        6.2.2.2 in Clause 7 (Docking Clause), the optional docking clause will apply;<\/p>\n<p>                        6.2.2.3 in Clause 9 (Use of Sub-processors), Option 2 will apply, and the time period for prior notice of Sub-processor changes shall be as set out in Clause 5.2. of this DPA;<\/p>\n<p>                        6.2.2.4 in Clause 11 (Redress), the optional language to permit data subjects to lodge complaints with an independent dispute resolution body will not apply;<\/p>\n<p>                        6.2.2.5 in Clause 17 (Governing Law), Option 1 will apply, and the EU SCCs will be governed by Dutch law;<\/p>\n<p>                        6.2.2.6 in Clause 18(b) (Choice of forum and jurisdiction), disputes shall be resolved before the courts of Amsterdam, the Netherlands;<\/p>\n<p>                        6.2.2.7 Annex I shall be deemed completed with the information set out in Annex 1 to this Agreement;<\/p>\n<p>                        6.2.2.8 Annex II shall be deemed completed with the information set out in Annex 3 to this DPA.<\/p><\/div>\n<p>                    6.2.3 In relation to transfers of Personal Data protected by UK GDPR or the Swiss DPA, the EU SCCs will also apply in accordance with Section 6.2.2. above, with the following modifications:<\/p>\n<div style=\"padding-left: 20px;\">\n                        6.2.3.1 references to &#8220;Regulation (EU) 2016\/679&#8221; shall be interpreted as references to UK GDPR or the Swiss DPA (as applicable);<\/p>\n<p>                        6.2.3.2 references to specific Articles of &#8220;Regulation (EU) 2016\/679&#8221; shall be replaced with the equivalent article or section of UK GDPR or the Swiss DPA (as applicable);<\/p>\n<p>                        6.2.3.3 references to &#8220;EU&#8221;, &#8220;Union&#8221;, &#8220;Member State&#8221; and &#8220;Member State law&#8221; shall be replaced with references to the &#8220;UK&#8221; or &#8220;Switzerland&#8221;, or &#8220;UK law&#8221; or &#8220;Swiss law&#8221; (as applicable);<\/p>\n<p>                        6.2.3.4 the term &#8220;member state&#8221; shall not be interpreted in such a way as to exclude data subjects in the UK or Switzerland from the possibility of suing for their rights in their place of habitual residence (i.e., the UK or Switzerland);<\/p>\n<p>                        6.2.3.5 Clause 13(a) and Part C of Annex 1 are not used and the &#8220;competent supervisory authority&#8221; is the United Kingdom Information Commissioner or Swiss Federal Data Protection Information Commissioner (as applicable);<\/p>\n<p>                        6.2.3.6 references to the &#8220;competent supervisory authority&#8221; and &#8220;competent courts&#8221; shall be replaced with references to the &#8220;Information Commissioner&#8221; and the &#8220;courts of England and Wales&#8221; or the &#8220;Swiss Federal Data Protection Information Commissioner&#8221; and &#8220;applicable courts of Switzerland&#8221; (as applicable);<\/p>\n<p>                        6.2.3.7 in Clause 17, the Standard Contractual Clauses shall be governed by the laws of England and Wales or Switzerland (as applicable); and<\/p>\n<p>                        6.2.3.8 with respect to transfers to which UK GDPR apply, Clause 18 shall be amended to state &#8220;Any dispute arising from these Clauses shall be resolved by the courts of England and Wales. A data subject may bring a legal proceeding against the data exporter and\/or data importer before the courts of any country in the UK. The Parties agree to submit themselves to the jurisdiction of such courts&#8221;, and with respect to transfers to which the Swiss DPA applies, Clause 18(b) shall state that disputes shall be resolved before the applicable courts of Switzerland.<\/p><\/div>\n<p>                    6.2.4 UK Transfers. To the extent that and for so long at the EU SCCs as implemented  above, cannot be used to lawfully transfer Personal Data in compliance with the UK GDPR,  the UK SCCs shall instead be incorporated by reference and form an integral part of this DPA and shall apply to such transfers of Personal Data governed by the UK GDPR.  Where this is the case, the relevant annexes, tables or appendices of the UK SCCs shall be populated using the relevant information contained in this DPA.<\/p><\/div>\n<p>                6.3 In the event that any provision of this DPA contradicts, directly or indirectly, the Standard Contractual Clauses, the appropriate Standard Contractual Clauses shall prevail to the extent of such conflict.<\/p>\n<p>                6.4 Alternative Transfer Mechanism. If Bloomreach adopts an alternative lawful data export mechanism for the transfer of Personal data not described in this DPA (&#8220;Alternative Transfer Mechanism&#8221;), the Alternative Transfer Mechanism shall apply instead of any applicable transfer mechanism described in this DPA (but only to the extent such Alternative Transfer Mechanism complies with EU\/UK Data Protection Law and extends to the territories to which the relevant Personal Data is transferred) subject to Customer\u2019s consent which cannot be unreasonably withheld.<\/p>\n<p>\n                <strong>7. LIMITATION OF LIABILITY<\/strong><\/p>\n<p>                7.1 Limitation of Liability. To the maximum extent permitted by law, each party and its Affiliates&#8217; aggregate liability to the other party arising out of or in relation to this DPA (including the Standard Contractual Clauses), whether in contract, tort or under any other theory of liability, will be subject to the limitations and exclusions of liability (including any agreed aggregate financial cap) set forth under the Agreement. For the avoidance of doubt, nothing in this DPA is intended to limit the rights a Data Subject may have against either Party arising out of such Party&#8217;s breach of the Standard Contractual Clauses, where applicable.<\/p>\n<p>\n                <strong>8. MISCELLANEOUS<\/strong><\/p>\n<p>                8.1 Third Party Beneficiaries. Data Subjects are the sole third party beneficiaries to the Standard Contractual Clauses, and there are no other third party beneficiaries to the Agreement and this DPA. Without prejudice to the foregoing, the Agreement and the terms of this DPA apply only to the Parties and do not confer any rights to any Customer\u2019s Affiliate, Customer\u2019s end user or any third-party Data Subjects.  <\/p>\n<p>                8.2 Governing Law and Jurisdiction. This DPA shall be governed by and construed with governing law and jurisdiction provisions in the Agreement, unless and to the extent required otherwise by the Data Protection Legislation or the Standard Contractual Clauses.  <\/p>\n<p>                8.3 Scope of this DPA. For the avoidance of doubt, the processing of information other than Personal Data for the Permitted Purposes does not fall under the scope of this DPA.<\/p>\n<p>                8.4 Term. This DPA will continue to be in effect for the term of the Agreement or any applicable Sales Order plus the period from expiry of the Agreement or Sales Order (as applicable) until Bloomreach ceases to process Personal Data on behalf of the Customer (the &#8220;Processing Term&#8221;).<\/p>\n<p>                <!-- \/ol --><\/p>\n<p dir=\"ltr\" style=\"line-height:1.2;text-align: center;margin-top:0pt;margin-bottom:0pt;\"><span id=\"docs-internal-guid-cf8bc203-7fff-0fa3-3bf6-06f8665bddcf\"><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">Annex 1<\/span><\/span><\/p>\n<p dir=\"ltr\" style=\"line-height:1.2;text-align: center;margin-top:0pt;margin-bottom:0pt;\"><span id=\"docs-internal-guid-cf8bc203-7fff-0fa3-3bf6-06f8665bddcf\"><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">Description of the Processing&nbsp;<\/span><\/span><\/p>\n<p>&nbsp;<\/p>\n<p dir=\"ltr\" style=\"line-height:1.2;text-align: justify;margin-top:12pt;margin-bottom:0pt;\"><span id=\"docs-internal-guid-cf8bc203-7fff-0fa3-3bf6-06f8665bddcf\"><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">Annex&nbsp; 1 (A) List of Parties:&nbsp;<\/span><\/span><\/p>\n<div align=\"left\" dir=\"ltr\" style=\"margin-left:-11.05pt;\">\n<table style=\"border:none;border-collapse:collapse;\">\n<colgroup>\n<col width=\"302\" \/>\n<col width=\"302\" \/>\n                        <\/colgroup>\n<tbody>\n<tr style=\"height:0pt\">\n<td style=\"border-left:solid #000000 0.5pt;border-right:solid #000000 0.5pt;border-bottom:solid #000000 0.5pt;border-top:solid #000000 0.5pt;vertical-align:top;background-color:#d0cece;padding:0pt 5.4pt 0pt 5.4pt;overflow:hidden;overflow-wrap:break-word;\">\n<p dir=\"ltr\" style=\"line-height:1.2;text-align: justify;margin-top:12pt;margin-bottom:0pt;\"><span id=\"docs-internal-guid-cf8bc203-7fff-0fa3-3bf6-06f8665bddcf\"><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">Customer<\/span><\/span><\/p>\n<\/td>\n<td style=\"border-left:solid #000000 0.5pt;border-right:solid #000000 0.5pt;border-bottom:solid #000000 0.5pt;border-top:solid #000000 0.5pt;vertical-align:top;background-color:#d0cece;padding:0pt 5.4pt 0pt 5.4pt;overflow:hidden;overflow-wrap:break-word;\">\n<p dir=\"ltr\" style=\"line-height:1.2;text-align: justify;margin-top:12pt;margin-bottom:0pt;\"><span id=\"docs-internal-guid-cf8bc203-7fff-0fa3-3bf6-06f8665bddcf\"><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">Bloomreach<\/span><\/span><\/p>\n<\/td>\n<\/tr>\n<tr style=\"height:0pt\">\n<td style=\"border-left:solid #000000 0.5pt;border-right:solid #000000 0.5pt;border-bottom:solid #000000 0.5pt;border-top:solid #000000 0.5pt;vertical-align:top;padding:0pt 5.4pt 0pt 5.4pt;overflow:hidden;overflow-wrap:break-word;\">\n<p dir=\"ltr\" style=\"line-height:1.2;text-align: justify;margin-top:12pt;margin-bottom:0pt;\"><span id=\"docs-internal-guid-cf8bc203-7fff-0fa3-3bf6-06f8665bddcf\"><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">Name: The entity identified as the &quot;Customer&quot; in the Agreement&nbsp;<\/span><\/span><\/p>\n<\/td>\n<td style=\"border-left:solid #000000 0.5pt;border-right:solid #000000 0.5pt;border-bottom:solid #000000 0.5pt;border-top:solid #000000 0.5pt;vertical-align:top;padding:0pt 5.4pt 0pt 5.4pt;overflow:hidden;overflow-wrap:break-word;\">\n<p dir=\"ltr\" style=\"line-height:1.2;text-align: justify;margin-top:12pt;margin-bottom:0pt;\"><span id=\"docs-internal-guid-cf8bc203-7fff-0fa3-3bf6-06f8665bddcf\"><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">Name: The entity identified as Bloomreach in the Agreement&nbsp;<\/span><\/span><\/p>\n<\/td>\n<\/tr>\n<tr style=\"height:0pt\">\n<td style=\"border-left:solid #000000 0.5pt;border-right:solid #000000 0.5pt;border-bottom:solid #000000 0.5pt;border-top:solid #000000 0.5pt;vertical-align:top;padding:0pt 5.4pt 0pt 5.4pt;overflow:hidden;overflow-wrap:break-word;\">\n<p dir=\"ltr\" style=\"line-height:1.2;text-align: justify;margin-top:12pt;margin-bottom:0pt;\"><span id=\"docs-internal-guid-cf8bc203-7fff-0fa3-3bf6-06f8665bddcf\"><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">Address:&nbsp; The address for the Customer associated with its Bloomreach account or as otherwise specified in the Sales Order or Agreement.&nbsp;&nbsp;<\/span><\/span><\/p>\n<\/td>\n<td style=\"border-left:solid #000000 0.5pt;border-right:solid #000000 0.5pt;border-bottom:solid #000000 0.5pt;border-top:solid #000000 0.5pt;vertical-align:top;padding:0pt 5.4pt 0pt 5.4pt;overflow:hidden;overflow-wrap:break-word;\">\n<p dir=\"ltr\" style=\"line-height:1.2;text-align: justify;margin-top:12pt;margin-bottom:0pt;\"><span id=\"docs-internal-guid-cf8bc203-7fff-0fa3-3bf6-06f8665bddcf\"><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">Address: &zwnj;Bloomreach address specified in the Agreement.&nbsp;<\/span><\/span><\/p>\n<\/td>\n<\/tr>\n<tr style=\"height:0pt\">\n<td style=\"border-left:solid #000000 0.5pt;border-right:solid #000000 0.5pt;border-bottom:solid #000000 0.5pt;border-top:solid #000000 0.5pt;vertical-align:top;padding:0pt 5.4pt 0pt 5.4pt;overflow:hidden;overflow-wrap:break-word;\">\n<p dir=\"ltr\" style=\"line-height:1.2;text-align: justify;margin-top:12pt;margin-bottom:0pt;\"><span id=\"docs-internal-guid-cf8bc203-7fff-0fa3-3bf6-06f8665bddcf\"><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">Contact Person&#39;s Name, position and contact details: The contact details associated with the Customer&#39;s Bloomreach account, or as otherwise specified in the Sales Order or Agreement.&nbsp;<\/span><\/span><\/p>\n<\/td>\n<td style=\"border-left:solid #000000 0.5pt;border-right:solid #000000 0.5pt;border-bottom:solid #000000 0.5pt;border-top:solid #000000 0.5pt;vertical-align:top;padding:0pt 5.4pt 0pt 5.4pt;overflow:hidden;overflow-wrap:break-word;\">\n<p dir=\"ltr\" style=\"line-height:1.2;text-align: justify;margin-top:12pt;margin-bottom:0pt;\"><span id=\"docs-internal-guid-cf8bc203-7fff-0fa3-3bf6-06f8665bddcf\"><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">Contact Person&#39;s Name, position and contact details:&nbsp; The contact details specified in the Agreement.<\/span><\/span><\/p>\n<\/td>\n<\/tr>\n<tr style=\"height:0pt\">\n<td style=\"border-left:solid #000000 0.5pt;border-right:solid #000000 0.5pt;border-bottom:solid #000000 0.5pt;border-top:solid #000000 0.5pt;vertical-align:top;padding:0pt 5.4pt 0pt 5.4pt;overflow:hidden;overflow-wrap:break-word;\">\n<p dir=\"ltr\" style=\"line-height:1.2;text-align: justify;margin-top:12pt;margin-bottom:0pt;\"><span id=\"docs-internal-guid-cf8bc203-7fff-0fa3-3bf6-06f8665bddcf\"><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">Activities relevant to the processing:&nbsp; See Annex 1(B) below<\/span><\/span><\/p>\n<\/td>\n<td style=\"border-left:solid #000000 0.5pt;border-right:solid #000000 0.5pt;border-bottom:solid #000000 0.5pt;border-top:solid #000000 0.5pt;vertical-align:top;padding:0pt 5.4pt 0pt 5.4pt;overflow:hidden;overflow-wrap:break-word;\">\n<p dir=\"ltr\" style=\"line-height:1.2;text-align: justify;margin-top:12pt;margin-bottom:0pt;\"><span id=\"docs-internal-guid-cf8bc203-7fff-0fa3-3bf6-06f8665bddcf\"><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">Activities relevant to the processing: See Annex 1(B) below&nbsp;<\/span><\/span><\/p>\n<\/td>\n<\/tr>\n<tr style=\"height:0pt\">\n<td style=\"border-left:solid #000000 0.5pt;border-right:solid #000000 0.5pt;border-bottom:solid #000000 0.5pt;border-top:solid #000000 0.5pt;vertical-align:top;padding:0pt 5.4pt 0pt 5.4pt;overflow:hidden;overflow-wrap:break-word;\">\n<p dir=\"ltr\" style=\"line-height:1.2;text-align: justify;margin-top:12pt;margin-bottom:0pt;\"><span id=\"docs-internal-guid-cf8bc203-7fff-0fa3-3bf6-06f8665bddcf\"><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">Role: Controller or Processor (as applicable)<\/span><\/span><\/p>\n<\/td>\n<td style=\"border-left:solid #000000 0.5pt;border-right:solid #000000 0.5pt;border-bottom:solid #000000 0.5pt;border-top:solid #000000 0.5pt;vertical-align:top;padding:0pt 5.4pt 0pt 5.4pt;overflow:hidden;overflow-wrap:break-word;\">\n<p dir=\"ltr\" style=\"line-height:1.2;text-align: justify;margin-top:12pt;margin-bottom:0pt;\"><span id=\"docs-internal-guid-cf8bc203-7fff-0fa3-3bf6-06f8665bddcf\"><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">Role: Processor or sub-processor (as applicable)<\/span><\/span><\/p>\n<\/td>\n<\/tr>\n<tr style=\"height:0pt\">\n<td style=\"border-left:solid #000000 0.5pt;border-right:solid #000000 0.5pt;border-bottom:solid #000000 0.5pt;border-top:solid #000000 0.5pt;vertical-align:top;padding:0pt 5.4pt 0pt 5.4pt;overflow:hidden;overflow-wrap:break-word;\">\n<p dir=\"ltr\" style=\"line-height:1.2;text-align: justify;margin-top:12pt;margin-bottom:0pt;\"><span id=\"docs-internal-guid-cf8bc203-7fff-0fa3-3bf6-06f8665bddcf\"><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">Role for the purpose of transfer under Clause 6 of the DPA: Data Exporter&nbsp;<\/span><\/span><\/p>\n<\/td>\n<td style=\"border-left:solid #000000 0.5pt;border-right:solid #000000 0.5pt;border-bottom:solid #000000 0.5pt;border-top:solid #000000 0.5pt;vertical-align:top;padding:0pt 5.4pt 0pt 5.4pt;overflow:hidden;overflow-wrap:break-word;\">\n<p dir=\"ltr\" style=\"line-height:1.2;text-align: justify;margin-top:12pt;margin-bottom:0pt;\"><span id=\"docs-internal-guid-cf8bc203-7fff-0fa3-3bf6-06f8665bddcf\"><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">Role for the purpose of transfer under Clause 6 of the DPA: Data Importer<\/span><\/span><\/p>\n<\/td>\n<\/tr>\n<tr style=\"height:0pt\">\n<td style=\"border-left:solid #000000 0.5pt;border-right:solid #000000 0.5pt;border-bottom:solid #000000 0.5pt;border-top:solid #000000 0.5pt;vertical-align:top;padding:0pt 5.4pt 0pt 5.4pt;overflow:hidden;overflow-wrap:break-word;\">\n<p dir=\"ltr\" style=\"line-height:1.2;text-align: justify;margin-top:12pt;margin-bottom:0pt;\"><span id=\"docs-internal-guid-cf8bc203-7fff-0fa3-3bf6-06f8665bddcf\"><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">Signature and Date:&nbsp; Subject to Clause 6 of the DPA, by using the Services to transfer Personal Data to Bloomreach located in a non-adequate country, the data exporter will be deemed to have signed this Annex 1.&nbsp;<\/span><\/span><\/p>\n<\/td>\n<td style=\"border-left:solid #000000 0.5pt;border-right:solid #000000 0.5pt;border-bottom:solid #000000 0.5pt;border-top:solid #000000 0.5pt;vertical-align:top;padding:0pt 5.4pt 0pt 5.4pt;overflow:hidden;overflow-wrap:break-word;\">\n<p dir=\"ltr\" style=\"line-height:1.2;text-align: justify;margin-top:12pt;margin-bottom:0pt;\"><span id=\"docs-internal-guid-cf8bc203-7fff-0fa3-3bf6-06f8665bddcf\"><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">Signature and Date: Subject to Clause 6 of the DPA,&nbsp; by transferring Personal Data to a non-adequate country on Customer&#39;s instruction, the data importer will be deemed to have signed this Annex 1.&nbsp;<\/span><\/span><\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table><\/div>\n<p>&nbsp;<\/p>\n<p dir=\"ltr\" style=\"line-height:1.2;text-align: justify;margin-top:12pt;margin-bottom:0pt;\"><span id=\"docs-internal-guid-cf8bc203-7fff-0fa3-3bf6-06f8665bddcf\"><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">Annex 1(B) Description of Processing Bloomreach Engagement:&nbsp;&nbsp;&nbsp;<\/span><\/span><\/p>\n<div align=\"left\" dir=\"ltr\" style=\"margin-left:-11.05pt;\">\n<table style=\"border:none;border-collapse:collapse;\">\n<colgroup>\n<col width=\"190\" \/>\n<col width=\"414\" \/>\n                        <\/colgroup>\n<tbody>\n<tr style=\"height:0pt\">\n<td style=\"border-left:solid #000000 0.5pt;border-right:solid #000000 0.5pt;border-bottom:solid #000000 0.5pt;border-top:solid #000000 0.5pt;vertical-align:top;padding:0pt 5.4pt 0pt 5.4pt;overflow:hidden;overflow-wrap:break-word;\">\n<p dir=\"ltr\" style=\"line-height:1.2;margin-top:0pt;margin-bottom:12pt;\"><span id=\"docs-internal-guid-cf8bc203-7fff-0fa3-3bf6-06f8665bddcf\"><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">Categories of <\/span><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; text-decoration-line: underline; text-decoration-skip-ink: none; vertical-align: baseline; \">&zwnj;<\/span><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">data <\/span><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; text-decoration-line: underline; text-decoration-skip-ink: none; vertical-align: baseline; \">&zwnj;<\/span><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">subjects whose Personal Data is processed:<\/span><\/span><\/p>\n<\/td>\n<td style=\"border-left:solid #000000 0.5pt;border-right:solid #000000 0.5pt;border-bottom:solid #000000 0.5pt;border-top:solid #000000 0.5pt;vertical-align:top;padding:0pt 5.4pt 0pt 5.4pt;overflow:hidden;overflow-wrap:break-word;\">\n<p dir=\"ltr\" style=\"line-height:1.2;margin-top:0pt;margin-bottom:12pt;\"><span id=\"docs-internal-guid-cf8bc203-7fff-0fa3-3bf6-06f8665bddcf\"><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">Depending on the nature and scope of the Services purchased by the Customer, the Data Subjects may include:&nbsp;<\/span><\/span><\/p>\n<ul style=\"margin-top:0;margin-bottom:0;padding-inline-start:48px;\">\n<li aria-level=\"1\" dir=\"ltr\" style=\"list-style-type: disc; font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline;  margin-left: -18pt;\">\n<p dir=\"ltr\" role=\"presentation\" style=\"line-height:1.2;margin-top:0pt;margin-bottom:0pt;\"><span id=\"docs-internal-guid-cf8bc203-7fff-0fa3-3bf6-06f8665bddcf\"><span style=\"font-size: 11pt; background-color: transparent; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">Visitors &#8211; any visitor to Customer&rsquo;s website covered by the Services.<\/span><\/span><\/p>\n<\/li>\n<li aria-level=\"1\" dir=\"ltr\" style=\"list-style-type: disc; font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline;  margin-left: -18pt;\">\n<p dir=\"ltr\" role=\"presentation\" style=\"line-height:1.2;margin-top:0pt;margin-bottom:6pt;\"><span id=\"docs-internal-guid-cf8bc203-7fff-0fa3-3bf6-06f8665bddcf\"><span style=\"font-size: 11pt; background-color: transparent; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">&zwnj;End Customers &ndash; any existing or future &zwnj;end-customer or prospect of Customer that visits Customer&rsquo;s website&nbsp; covered by the Services or whose personal data is otherwise uploaded by Customer to the Services.&nbsp;<\/span><\/span><\/p>\n<\/li>\n<li aria-level=\"1\" dir=\"ltr\" style=\"list-style-type: disc; font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline;  margin-left: -18pt;\">\n<p dir=\"ltr\" role=\"presentation\" style=\"line-height:1.2;margin-top:0pt;margin-bottom:6pt;\"><span id=\"docs-internal-guid-cf8bc203-7fff-0fa3-3bf6-06f8665bddcf\"><span style=\"font-size: 11pt; background-color: transparent; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">Permitted Users &ndash; any of Customer&#39;s employees&zwnj; or other personnel, suppliers and other third parties who are authorized under the Agreement to use the Services.<\/span><\/span><\/p>\n<\/li>\n<\/ul>\n<\/td>\n<\/tr>\n<tr style=\"height:0pt\">\n<td style=\"border-left:solid #000000 0.5pt;border-right:solid #000000 0.5pt;border-bottom:solid #000000 0.5pt;border-top:solid #000000 0.5pt;vertical-align:top;padding:0pt 5.4pt 0pt 5.4pt;overflow:hidden;overflow-wrap:break-word;\">\n<p dir=\"ltr\" style=\"line-height:1.2;margin-top:0pt;margin-bottom:0pt;\"><span id=\"docs-internal-guid-cf8bc203-7fff-0fa3-3bf6-06f8665bddcf\"><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">Categories of <\/span><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; text-decoration-line: underline; text-decoration-skip-ink: none; vertical-align: baseline; \">&zwnj;<\/span><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">Personal <\/span><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; text-decoration-line: underline; text-decoration-skip-ink: none; vertical-align: baseline; \">&zwnj;&zwnj;<\/span><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">Data processed :&nbsp;<\/span><\/span><\/p>\n<\/td>\n<td style=\"border-left:solid #000000 0.5pt;border-right:solid #000000 0.5pt;border-bottom:solid #000000 0.5pt;border-top:solid #000000 0.5pt;vertical-align:top;padding:0pt 5.4pt 0pt 5.4pt;overflow:hidden;overflow-wrap:break-word;\">\n<p dir=\"ltr\" style=\"line-height:1.2;margin-top:0pt;margin-bottom:12pt;\"><span id=\"docs-internal-guid-cf8bc203-7fff-0fa3-3bf6-06f8665bddcf\"><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">Depending on the &zwnj;nature and scope of the Services, the Personal Data may include:<\/span><\/span><\/p>\n<ul style=\"margin-top:0;margin-bottom:0;padding-inline-start:48px;\">\n<li aria-level=\"1\" dir=\"ltr\" style=\"list-style-type: disc; font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline;  margin-left: -18pt;\">\n<p dir=\"ltr\" role=\"presentation\" style=\"line-height:1.2;margin-top:12pt;margin-bottom:0pt;\"><span id=\"docs-internal-guid-cf8bc203-7fff-0fa3-3bf6-06f8665bddcf\"><span style=\"font-size: 11pt; background-color: transparent; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">Permitted Users: identification and contact data (name, email address); IT related data (computer ID, user ID, password, IP address, log files).<\/span><\/span><\/p>\n<\/li>\n<li aria-level=\"1\" dir=\"ltr\" style=\"list-style-type: disc; font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline;  margin-left: -18pt;\">\n<p dir=\"ltr\" role=\"presentation\" style=\"line-height:1.2;margin-top:0pt;margin-bottom:0pt;\"><span id=\"docs-internal-guid-cf8bc203-7fff-0fa3-3bf6-06f8665bddcf\"><span style=\"font-size: 11pt; background-color: transparent; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">Visitors and End Customers: tracking data with respect to a specific product, tracking and other data contained in the contact forms; information about the preferences of contacting and Customer&rsquo;s services and limited location data (city); IP address; name, surname; gender; email address; login, information; time zone setting; operating system and platform; information about visits including the URL, the search terms, information about what the Customer viewed or searched on the Customer&rsquo;s website, page response times; download errors, length of visits to certain pages, page interaction information, (such as scrolling, clicks, and mouse-overs) and the methods used to browse away from the page; activities of users browsing web pages.<\/span><\/span><\/p>\n<\/li>\n<\/ul>\n<\/td>\n<\/tr>\n<tr style=\"height:0pt\">\n<td style=\"border-left:solid #000000 0.5pt;border-right:solid #000000 0.5pt;border-bottom:solid #000000 0.5pt;border-top:solid #000000 0.5pt;vertical-align:top;padding:0pt 5.4pt 0pt 5.4pt;overflow:hidden;overflow-wrap:break-word;\">\n<p dir=\"ltr\" style=\"line-height:1.2;margin-top:0pt;margin-bottom:0pt;\"><span id=\"docs-internal-guid-cf8bc203-7fff-0fa3-3bf6-06f8665bddcf\"><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; text-decoration-line: underline; text-decoration-skip-ink: none; vertical-align: baseline; \">&zwnj;<\/span><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">Special categories of&nbsp; data:<\/span><\/span><\/p>\n<\/td>\n<td style=\"border-left:solid #000000 0.5pt;border-right:solid #000000 0.5pt;border-bottom:solid #000000 0.5pt;border-top:solid #000000 0.5pt;vertical-align:top;padding:0pt 5.4pt 0pt 5.4pt;overflow:hidden;overflow-wrap:break-word;\">\n<p dir=\"ltr\" style=\"line-height:1.2;margin-top:0pt;margin-bottom:0pt;\"><span id=\"docs-internal-guid-cf8bc203-7fff-0fa3-3bf6-06f8665bddcf\"><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">&zwnj;Bloomreach does not require &zwnj;any special categories of&zwnj; data in order to provide the Services and does not intentionally collect or process any special categories of &zwnj;such data in connection with the provision of the Services.&nbsp;<\/span><\/span><\/p>\n<p dir=\"ltr\" style=\"line-height:1.2;margin-top:0pt;margin-bottom:0pt;\"><span id=\"docs-internal-guid-cf8bc203-7fff-0fa3-3bf6-06f8665bddcf\"><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">&nbsp;<\/span><\/span><\/p>\n<\/td>\n<\/tr>\n<tr style=\"height:0pt\">\n<td style=\"border-left:solid #000000 0.5pt;border-right:solid #000000 0.5pt;border-bottom:solid #000000 0.5pt;border-top:solid #000000 0.5pt;vertical-align:top;padding:0pt 5.4pt 0pt 5.4pt;overflow:hidden;overflow-wrap:break-word;\">\n<p dir=\"ltr\" style=\"line-height:1.2;margin-top:0pt;margin-bottom:0pt;\"><span id=\"docs-internal-guid-cf8bc203-7fff-0fa3-3bf6-06f8665bddcf\"><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">Frequency of the processing:<\/span><\/span><\/p>\n<\/td>\n<td style=\"border-left:solid #000000 0.5pt;border-right:solid #000000 0.5pt;border-bottom:solid #000000 0.5pt;border-top:solid #000000 0.5pt;vertical-align:top;padding:0pt 5.4pt 0pt 5.4pt;overflow:hidden;overflow-wrap:break-word;\">\n<p dir=\"ltr\" style=\"line-height:1.2;margin-top:0pt;margin-bottom:0pt;\"><span id=\"docs-internal-guid-cf8bc203-7fff-0fa3-3bf6-06f8665bddcf\"><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">Continuous basis depending on the use of the Services.&nbsp;<\/span><\/span><\/p>\n<\/td>\n<\/tr>\n<tr style=\"height:0pt\">\n<td style=\"border-left:solid #000000 0.5pt;border-right:solid #000000 0.5pt;border-bottom:solid #000000 0.5pt;border-top:solid #000000 0.5pt;vertical-align:top;padding:0pt 5.4pt 0pt 5.4pt;overflow:hidden;overflow-wrap:break-word;\">\n<p dir=\"ltr\" style=\"line-height:1.2;margin-top:0pt;margin-bottom:0pt;\"><span id=\"docs-internal-guid-cf8bc203-7fff-0fa3-3bf6-06f8665bddcf\"><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; text-decoration-line: underline; text-decoration-skip-ink: none; vertical-align: baseline; \">&zwnj;<\/span><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">Nature of processing:<\/span><\/span><\/p>\n<\/td>\n<td style=\"border-left:solid #000000 0.5pt;border-right:solid #000000 0.5pt;border-bottom:solid #000000 0.5pt;border-top:solid #000000 0.5pt;vertical-align:top;padding:0pt 5.4pt 0pt 5.4pt;overflow:hidden;overflow-wrap:break-word;\">\n<p dir=\"ltr\" style=\"line-height:1.2;margin-top:12pt;margin-bottom:0pt;\"><span id=\"docs-internal-guid-cf8bc203-7fff-0fa3-3bf6-06f8665bddcf\"><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">The nature of the Processing is the performance of the Services pursuant to the Agreement.&nbsp;<\/span><\/span><\/p>\n<\/td>\n<\/tr>\n<tr style=\"height:0pt\">\n<td style=\"border-left:solid #000000 0.5pt;border-right:solid #000000 0.5pt;border-bottom:solid #000000 0.5pt;border-top:solid #000000 0.5pt;vertical-align:top;padding:0pt 5.4pt 0pt 5.4pt;overflow:hidden;overflow-wrap:break-word;\">\n<p dir=\"ltr\" style=\"line-height:1.2;margin-top:0pt;margin-bottom:0pt;\"><span id=\"docs-internal-guid-cf8bc203-7fff-0fa3-3bf6-06f8665bddcf\"><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">Duration of the processing:&nbsp;&nbsp;<\/span><\/span><\/p>\n<\/td>\n<td style=\"border-left:solid #000000 0.5pt;border-right:solid #000000 0.5pt;border-bottom:solid #000000 0.5pt;border-top:solid #000000 0.5pt;vertical-align:top;padding:0pt 5.4pt 0pt 5.4pt;overflow:hidden;overflow-wrap:break-word;\">\n<p dir=\"ltr\" style=\"line-height:1.2;margin-top:0pt;margin-bottom:10pt;\"><span id=\"docs-internal-guid-cf8bc203-7fff-0fa3-3bf6-06f8665bddcf\"><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">The Processing Term.&nbsp;&nbsp;<\/span><\/span><\/p>\n<\/td>\n<\/tr>\n<tr style=\"height:0pt\">\n<td style=\"border-left:solid #000000 0.5pt;border-right:solid #000000 0.5pt;border-bottom:solid #000000 0.5pt;border-top:solid #000000 0.5pt;vertical-align:top;padding:0pt 5.4pt 0pt 5.4pt;overflow:hidden;overflow-wrap:break-word;\">\n<p dir=\"ltr\" style=\"line-height:1.2;margin-top:0pt;margin-bottom:0pt;\"><span id=\"docs-internal-guid-cf8bc203-7fff-0fa3-3bf6-06f8665bddcf\"><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">Purpose(s) of the data&nbsp; processing:&nbsp;<\/span><\/span><\/p>\n<\/td>\n<td style=\"border-left:solid #000000 0.5pt;border-right:solid #000000 0.5pt;border-bottom:solid #000000 0.5pt;border-top:solid #000000 0.5pt;vertical-align:top;padding:0pt 5.4pt 0pt 5.4pt;overflow:hidden;overflow-wrap:break-word;\">\n<p dir=\"ltr\" style=\"line-height:1.2;margin-top:0pt;margin-bottom:0pt;\"><span id=\"docs-internal-guid-cf8bc203-7fff-0fa3-3bf6-06f8665bddcf\"><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">(i) Processing to provide, maintain, support and improve Services provided to Customer in accordance with the Agreement and applicable Sales Order;&nbsp;<\/span><\/span><\/p>\n<p dir=\"ltr\" style=\"line-height:1.2;margin-top:0pt;margin-bottom:0pt;\"><span id=\"docs-internal-guid-cf8bc203-7fff-0fa3-3bf6-06f8665bddcf\"><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">(ii) Processing initiated by Permitted Users in their use of the Services; and&nbsp;<\/span><\/span><\/p>\n<p dir=\"ltr\" style=\"line-height:1.2;margin-top:0pt;margin-bottom:0pt;\"><span id=\"docs-internal-guid-cf8bc203-7fff-0fa3-3bf6-06f8665bddcf\"><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">(iii) Processing to comply with other documented reasonable instructions provided by Customer (e.g. via email) where such instructions are consistent with the terms of the Agreement (including this DPA).&nbsp;<\/span><\/span><\/p>\n<\/td>\n<\/tr>\n<tr style=\"height:0pt\">\n<td style=\"border-left:solid #000000 0.5pt;border-right:solid #000000 0.5pt;border-bottom:solid #000000 0.5pt;border-top:solid #000000 0.5pt;vertical-align:top;padding:0pt 5.4pt 0pt 5.4pt;overflow:hidden;overflow-wrap:break-word;\">\n<p dir=\"ltr\" style=\"line-height:1.2;margin-top:0pt;margin-bottom:0pt;\"><span id=\"docs-internal-guid-cf8bc203-7fff-0fa3-3bf6-06f8665bddcf\"><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">The period for which the Personal Data will be retained, or, if that is not possible, the criteria used to determine that period:&nbsp;<\/span><\/span><\/p>\n<\/td>\n<td style=\"border-left:solid #000000 0.5pt;border-right:solid #000000 0.5pt;border-bottom:solid #000000 0.5pt;border-top:solid #000000 0.5pt;vertical-align:top;padding:0pt 5.4pt 0pt 5.4pt;overflow:hidden;overflow-wrap:break-word;\">\n<p dir=\"ltr\" style=\"line-height:1.2;margin-top:0pt;margin-bottom:0pt;\"><span id=\"docs-internal-guid-cf8bc203-7fff-0fa3-3bf6-06f8665bddcf\"><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">Customer determines the duration of the Processing in accordance with the terms of this DPA.&nbsp;<\/span><\/span><\/p>\n<\/td>\n<\/tr>\n<tr style=\"height:0pt\">\n<td style=\"border-left:solid #000000 0.5pt;border-right:solid #000000 0.5pt;border-bottom:solid #000000 0.5pt;border-top:solid #000000 0.5pt;vertical-align:top;padding:0pt 5.4pt 0pt 5.4pt;overflow:hidden;overflow-wrap:break-word;\">\n<p dir=\"ltr\" style=\"line-height:1.2;margin-top:0pt;margin-bottom:0pt;\"><span id=\"docs-internal-guid-cf8bc203-7fff-0fa3-3bf6-06f8665bddcf\"><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">For transfers to (sub-) processors, also specify subject matter, nature and duration of the processing:<\/span><\/span><\/p>\n<\/td>\n<td style=\"border-left:solid #000000 0.5pt;border-right:solid #000000 0.5pt;border-bottom:solid #000000 0.5pt;border-top:solid #000000 0.5pt;vertical-align:top;padding:0pt 5.4pt 0pt 5.4pt;overflow:hidden;overflow-wrap:break-word;\">\n<p dir=\"ltr\" style=\"line-height:1.2;margin-top:0pt;margin-bottom:0pt;\"><span id=\"docs-internal-guid-cf8bc203-7fff-0fa3-3bf6-06f8665bddcf\"><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">As above.&nbsp;<\/span><\/span><\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table><\/div>\n<p>&nbsp;<\/p>\n<p dir=\"ltr\" style=\"line-height:1.2;text-align: justify;margin-top:12pt;margin-bottom:0pt;\"><span id=\"docs-internal-guid-cf8bc203-7fff-0fa3-3bf6-06f8665bddcf\"><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">Other Bloomreach Services:<\/span><\/span><\/p>\n<p>&nbsp;<\/p>\n<div align=\"left\" dir=\"ltr\" style=\"margin-left:-11.05pt;\">\n<table style=\"border:none;border-collapse:collapse;\">\n<colgroup>\n<col width=\"190\" \/>\n<col width=\"414\" \/>\n                        <\/colgroup>\n<tbody>\n<tr style=\"height:0pt\">\n<td style=\"border-left:solid #000000 0.5pt;border-right:solid #000000 0.5pt;border-bottom:solid #000000 0.5pt;border-top:solid #000000 0.5pt;vertical-align:top;padding:0pt 5.4pt 0pt 5.4pt;overflow:hidden;overflow-wrap:break-word;\">\n<p dir=\"ltr\" style=\"line-height:1.2;margin-top:0pt;margin-bottom:12pt;\"><span id=\"docs-internal-guid-cf8bc203-7fff-0fa3-3bf6-06f8665bddcf\"><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">Categories of <\/span><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; text-decoration-line: underline; text-decoration-skip-ink: none; vertical-align: baseline; \">&zwnj;<\/span><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">data <\/span><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; text-decoration-line: underline; text-decoration-skip-ink: none; vertical-align: baseline; \">&zwnj;<\/span><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">subjects whose Personal Data is processed :<\/span><\/span><\/p>\n<\/td>\n<td style=\"border-left:solid #000000 0.5pt;border-right:solid #000000 0.5pt;border-bottom:solid #000000 0.5pt;border-top:solid #000000 0.5pt;vertical-align:top;padding:0pt 5.4pt 0pt 5.4pt;overflow:hidden;overflow-wrap:break-word;\">\n<p dir=\"ltr\" style=\"line-height:1.2;margin-top:0pt;margin-bottom:12pt;\"><span id=\"docs-internal-guid-cf8bc203-7fff-0fa3-3bf6-06f8665bddcf\"><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">Depending on the nature of the Services purchased by the Customer, the Data Subjects may include:&nbsp;<\/span><\/span><\/p>\n<ul style=\"margin-top:0;margin-bottom:0;padding-inline-start:48px;\">\n<li aria-level=\"1\" dir=\"ltr\" style=\"list-style-type: disc; font-size: 11pt; font-family: Arial; color: rgb(255, 255, 255); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline;  margin-left: -18pt;\">\n<p dir=\"ltr\" role=\"presentation\" style=\"line-height:1.2;margin-top:12pt;margin-bottom:0pt;\"><span id=\"docs-internal-guid-cf8bc203-7fff-0fa3-3bf6-06f8665bddcf\"><span style=\"font-size: 11pt; color: rgb(0, 0, 0); background-color: transparent; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">Permitted Users &ndash; any of Customer&#39;s employees&zwnj; or other personnel, suppliers and other third parties who are authorized under the Agreement to use the Services.<\/span><\/span><\/p>\n<\/li>\n<li aria-level=\"1\" dir=\"ltr\" style=\"list-style-type: disc; font-size: 11pt; font-family: Arial; color: rgb(255, 255, 255); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline;  margin-left: -18pt;\">\n<p dir=\"ltr\" role=\"presentation\" style=\"line-height:1.2;margin-top:0pt;margin-bottom:0pt;\"><span id=\"docs-internal-guid-cf8bc203-7fff-0fa3-3bf6-06f8665bddcf\"><span style=\"font-size: 11pt; color: rgb(0, 0, 0); background-color: transparent; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">Visitors &#8211; any visitor to a Site covered by the Services.<\/span><\/span><\/p>\n<\/li>\n<li aria-level=\"1\" dir=\"ltr\" style=\"list-style-type: disc; font-size: 11pt; font-family: Arial; color: rgb(255, 255, 255); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline;  margin-left: -18pt;\">\n<p dir=\"ltr\" role=\"presentation\" style=\"line-height:1.2;margin-top:0pt;margin-bottom:6pt;\"><span id=\"docs-internal-guid-cf8bc203-7fff-0fa3-3bf6-06f8665bddcf\"><span style=\"font-size: 11pt; color: rgb(0, 0, 0); background-color: transparent; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">&zwnj;End Customers &ndash; any existing or future &zwnj;end-customer or prospect of Customer that visits a Site covered by the Services or whose personal data is otherwise uploaded by Customer to the Services.&nbsp;<\/span><\/span><\/p>\n<\/li>\n<\/ul>\n<\/td>\n<\/tr>\n<tr style=\"height:0pt\">\n<td style=\"border-left:solid #000000 0.5pt;border-right:solid #000000 0.5pt;border-bottom:solid #000000 0.5pt;border-top:solid #000000 0.5pt;vertical-align:top;padding:0pt 5.4pt 0pt 5.4pt;overflow:hidden;overflow-wrap:break-word;\">\n<p dir=\"ltr\" style=\"line-height:1.2;margin-top:0pt;margin-bottom:0pt;\"><span id=\"docs-internal-guid-cf8bc203-7fff-0fa3-3bf6-06f8665bddcf\"><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">Categories of <\/span><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; text-decoration-line: underline; text-decoration-skip-ink: none; vertical-align: baseline; \">&zwnj;<\/span><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">Personal <\/span><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; text-decoration-line: underline; text-decoration-skip-ink: none; vertical-align: baseline; \">&zwnj;&zwnj;<\/span><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">Data processed :&nbsp;<\/span><\/span><\/p>\n<\/td>\n<td style=\"border-left:solid #000000 0.5pt;border-right:solid #000000 0.5pt;border-bottom:solid #000000 0.5pt;border-top:solid #000000 0.5pt;vertical-align:top;padding:0pt 5.4pt 0pt 5.4pt;overflow:hidden;overflow-wrap:break-word;\">\n<p dir=\"ltr\" style=\"line-height:1.2;margin-top:0pt;margin-bottom:12pt;\"><span id=\"docs-internal-guid-cf8bc203-7fff-0fa3-3bf6-06f8665bddcf\"><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">Depending on the &zwnj;nature of the Services, the Personal Data may include:<\/span><\/span><\/p>\n<ul style=\"margin-top:0;margin-bottom:0;padding-inline-start:48px;\">\n<li aria-level=\"1\" dir=\"ltr\" style=\"list-style-type: disc; font-size: 11pt; font-family: Arial; color: rgb(255, 255, 255); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline;  margin-left: -18pt;\">\n<p dir=\"ltr\" role=\"presentation\" style=\"line-height:1.2;margin-top:12pt;margin-bottom:0pt;\"><span id=\"docs-internal-guid-cf8bc203-7fff-0fa3-3bf6-06f8665bddcf\"><span style=\"font-size: 11pt; color: rgb(0, 0, 0); background-color: transparent; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">Permitted Users: identification and contact data (name, address, title, contact details, username); financial information (credit card details, account details, payment information); employment details (employer, job title, geographic location, area of responsibility); IT related data (computer ID, user ID, password, IP address, log files).<\/span><\/span><\/p>\n<\/li>\n<li aria-level=\"1\" dir=\"ltr\" style=\"list-style-type: disc; font-size: 11pt; font-family: Arial; color: rgb(255, 255, 255); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline;  margin-left: -18pt;\">\n<p dir=\"ltr\" role=\"presentation\" style=\"line-height:1.2;margin-top:0pt;margin-bottom:0pt;\"><span id=\"docs-internal-guid-cf8bc203-7fff-0fa3-3bf6-06f8665bddcf\"><span style=\"font-size: 11pt; color: rgb(0, 0, 0); background-color: transparent; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">Visitors: browsing and purchasing activity (including pages and\/or products purchases, links clicked, searched performed, product category and order details). IP addresses, unique device level identifiers (such as an IDFA or Android Advertising ID), cookies data, online navigation data (including access date and times), location data, browser data language and any other Personal Data Customer configures the Services to collect.<\/span><\/span><\/p>\n<\/li>\n<li aria-level=\"1\" dir=\"ltr\" style=\"list-style-type: disc; font-size: 11pt; font-family: Arial; color: rgb(255, 255, 255); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline;  margin-left: -18pt;\">\n<p dir=\"ltr\" role=\"presentation\" style=\"line-height:1.2;margin-top:0pt;margin-bottom:12pt;\"><span id=\"docs-internal-guid-cf8bc203-7fff-0fa3-3bf6-06f8665bddcf\"><span style=\"font-size: 11pt; color: rgb(0, 0, 0); background-color: transparent; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">&zwnj;End Customers: tracking data with respect to a specific product, tracking and other data contained in the contact forms; information about the preferences of contacting and Customer&rsquo;s services and limited location data (city); IP address; name, surname; gender; email address; login, information; time zone setting; operating system and platform; information about visits including the URL, the search terms, information about what the Customer viewed or searched on the Customer&rsquo;s website, page response times; download errors, length of visits to certain pages, page interaction information, (such as scrolling, clicks, and mouse-overs) and the methods used to browse away from the page, and activities of users browsing web pages.<\/span><\/span><\/p>\n<\/li>\n<\/ul>\n<p dir=\"ltr\" style=\"line-height:1.2;margin-top:12pt;margin-bottom:0pt;\"><span id=\"docs-internal-guid-cf8bc203-7fff-0fa3-3bf6-06f8665bddcf\"><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">&nbsp;<\/span><\/span><\/p>\n<\/td>\n<\/tr>\n<tr style=\"height:0pt\">\n<td style=\"border-left:solid #000000 0.5pt;border-right:solid #000000 0.5pt;border-bottom:solid #000000 0.5pt;border-top:solid #000000 0.5pt;vertical-align:top;padding:0pt 5.4pt 0pt 5.4pt;overflow:hidden;overflow-wrap:break-word;\">\n<p dir=\"ltr\" style=\"line-height:1.2;margin-top:0pt;margin-bottom:0pt;\"><span id=\"docs-internal-guid-cf8bc203-7fff-0fa3-3bf6-06f8665bddcf\"><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; text-decoration-line: underline; text-decoration-skip-ink: none; vertical-align: baseline; \">&zwnj;<\/span><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">Special categories of&nbsp; data:<\/span><\/span><\/p>\n<\/td>\n<td style=\"border-left:solid #000000 0.5pt;border-right:solid #000000 0.5pt;border-bottom:solid #000000 0.5pt;border-top:solid #000000 0.5pt;vertical-align:top;padding:0pt 5.4pt 0pt 5.4pt;overflow:hidden;overflow-wrap:break-word;\">\n<p dir=\"ltr\" style=\"line-height:1.2;margin-top:0pt;margin-bottom:0pt;\"><span id=\"docs-internal-guid-cf8bc203-7fff-0fa3-3bf6-06f8665bddcf\"><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">&zwnj;Bloomreach does not require &zwnj;any special categories of&zwnj; data in order to provide the Services and does not intentionally collect or process any special categories of &zwnj;such data in connection with the provision of the Services.&nbsp;<\/span><\/span><\/p>\n<p dir=\"ltr\" style=\"line-height:1.2;margin-top:0pt;margin-bottom:0pt;\"><span id=\"docs-internal-guid-cf8bc203-7fff-0fa3-3bf6-06f8665bddcf\"><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">&nbsp;<\/span><\/span><\/p>\n<\/td>\n<\/tr>\n<tr style=\"height:0pt\">\n<td style=\"border-left:solid #000000 0.5pt;border-right:solid #000000 0.5pt;border-bottom:solid #000000 0.5pt;border-top:solid #000000 0.5pt;vertical-align:top;padding:0pt 5.4pt 0pt 5.4pt;overflow:hidden;overflow-wrap:break-word;\">\n<p dir=\"ltr\" style=\"line-height:1.2;margin-top:0pt;margin-bottom:0pt;\"><span id=\"docs-internal-guid-cf8bc203-7fff-0fa3-3bf6-06f8665bddcf\"><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">Frequency of the transfer:<\/span><\/span><\/p>\n<\/td>\n<td style=\"border-left:solid #000000 0.5pt;border-right:solid #000000 0.5pt;border-bottom:solid #000000 0.5pt;border-top:solid #000000 0.5pt;vertical-align:top;padding:0pt 5.4pt 0pt 5.4pt;overflow:hidden;overflow-wrap:break-word;\">\n<p dir=\"ltr\" style=\"line-height:1.2;margin-top:0pt;margin-bottom:0pt;\"><span id=\"docs-internal-guid-cf8bc203-7fff-0fa3-3bf6-06f8665bddcf\"><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">Continuous basis depending on the use of the Services.&nbsp;<\/span><\/span><\/p>\n<\/td>\n<\/tr>\n<tr style=\"height:0pt\">\n<td style=\"border-left:solid #000000 0.5pt;border-right:solid #000000 0.5pt;border-bottom:solid #000000 0.5pt;border-top:solid #000000 0.5pt;vertical-align:top;padding:0pt 5.4pt 0pt 5.4pt;overflow:hidden;overflow-wrap:break-word;\">\n<p dir=\"ltr\" style=\"line-height:1.2;margin-top:0pt;margin-bottom:0pt;\"><span id=\"docs-internal-guid-cf8bc203-7fff-0fa3-3bf6-06f8665bddcf\"><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; text-decoration-line: underline; text-decoration-skip-ink: none; vertical-align: baseline; \">&zwnj;<\/span><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">Nature of processing:<\/span><\/span><\/p>\n<\/td>\n<td style=\"border-left:solid #000000 0.5pt;border-right:solid #000000 0.5pt;border-bottom:solid #000000 0.5pt;border-top:solid #000000 0.5pt;vertical-align:top;padding:0pt 5.4pt 0pt 5.4pt;overflow:hidden;overflow-wrap:break-word;\">\n<p dir=\"ltr\" style=\"line-height:1.2;margin-top:12pt;margin-bottom:0pt;\"><span id=\"docs-internal-guid-cf8bc203-7fff-0fa3-3bf6-06f8665bddcf\"><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">The nature of the Processing is the performance of the Services pursuant to the Agreement.&nbsp;<\/span><\/span><\/p>\n<\/td>\n<\/tr>\n<tr style=\"height:0pt\">\n<td style=\"border-left:solid #000000 0.5pt;border-right:solid #000000 0.5pt;border-bottom:solid #000000 0.5pt;border-top:solid #000000 0.5pt;vertical-align:top;padding:0pt 5.4pt 0pt 5.4pt;overflow:hidden;overflow-wrap:break-word;\">\n<p dir=\"ltr\" style=\"line-height:1.2;margin-top:0pt;margin-bottom:0pt;\"><span id=\"docs-internal-guid-cf8bc203-7fff-0fa3-3bf6-06f8665bddcf\"><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">Duration of the processing:&nbsp;&nbsp;<\/span><\/span><\/p>\n<\/td>\n<td style=\"border-left:solid #000000 0.5pt;border-right:solid #000000 0.5pt;border-bottom:solid #000000 0.5pt;border-top:solid #000000 0.5pt;vertical-align:top;padding:0pt 5.4pt 0pt 5.4pt;overflow:hidden;overflow-wrap:break-word;\">\n<p dir=\"ltr\" style=\"line-height:1.2;margin-top:0pt;margin-bottom:10pt;\"><span id=\"docs-internal-guid-cf8bc203-7fff-0fa3-3bf6-06f8665bddcf\"><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">The Processing Term.&nbsp;&nbsp;<\/span><\/span><\/p>\n<\/td>\n<\/tr>\n<tr style=\"height:0pt\">\n<td style=\"border-left:solid #000000 0.5pt;border-right:solid #000000 0.5pt;border-bottom:solid #000000 0.5pt;border-top:solid #000000 0.5pt;vertical-align:top;padding:0pt 5.4pt 0pt 5.4pt;overflow:hidden;overflow-wrap:break-word;\">\n<p dir=\"ltr\" style=\"line-height:1.2;margin-top:0pt;margin-bottom:0pt;\"><span id=\"docs-internal-guid-cf8bc203-7fff-0fa3-3bf6-06f8665bddcf\"><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">Purpose(s) of the data processing:&nbsp;<\/span><\/span><\/p>\n<\/td>\n<td style=\"border-left:solid #000000 0.5pt;border-right:solid #000000 0.5pt;border-bottom:solid #000000 0.5pt;border-top:solid #000000 0.5pt;vertical-align:top;padding:0pt 5.4pt 0pt 5.4pt;overflow:hidden;overflow-wrap:break-word;\">\n<p dir=\"ltr\" style=\"line-height:1.2;margin-top:0pt;margin-bottom:0pt;\"><span id=\"docs-internal-guid-cf8bc203-7fff-0fa3-3bf6-06f8665bddcf\"><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">(i) Processing to provide, maintain, support and improve Services provided to Customer in accordance with the Agreement and applicable Sales Order;&nbsp;<\/span><\/span><\/p>\n<p dir=\"ltr\" style=\"line-height:1.2;margin-top:0pt;margin-bottom:0pt;\"><span id=\"docs-internal-guid-cf8bc203-7fff-0fa3-3bf6-06f8665bddcf\"><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">(ii) Processing initiated by Permitted Users in their use of the Services; and&nbsp;<\/span><\/span><\/p>\n<p dir=\"ltr\" style=\"line-height:1.2;margin-top:0pt;margin-bottom:0pt;\"><span id=\"docs-internal-guid-cf8bc203-7fff-0fa3-3bf6-06f8665bddcf\"><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">(iii) Processing to comply with other documented reasonable instructions provided by Customer (e.g. via email) where such instructions are consistent with the terms of the Agreement (including this DPA).&nbsp;<\/span><\/span><\/p>\n<\/td>\n<\/tr>\n<tr style=\"height:0pt\">\n<td style=\"border-left:solid #000000 0.5pt;border-right:solid #000000 0.5pt;border-bottom:solid #000000 0.5pt;border-top:solid #000000 0.5pt;vertical-align:top;padding:0pt 5.4pt 0pt 5.4pt;overflow:hidden;overflow-wrap:break-word;\">\n<p dir=\"ltr\" style=\"line-height:1.2;margin-top:0pt;margin-bottom:0pt;\"><span id=\"docs-internal-guid-cf8bc203-7fff-0fa3-3bf6-06f8665bddcf\"><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">The period for which the Personal Data will be retained, or, if that is not possible, the criteria used to determine that period:&nbsp;<\/span><\/span><\/p>\n<\/td>\n<td style=\"border-left:solid #000000 0.5pt;border-right:solid #000000 0.5pt;border-bottom:solid #000000 0.5pt;border-top:solid #000000 0.5pt;vertical-align:top;padding:0pt 5.4pt 0pt 5.4pt;overflow:hidden;overflow-wrap:break-word;\">\n<p dir=\"ltr\" style=\"line-height:1.2;margin-top:0pt;margin-bottom:0pt;\"><span id=\"docs-internal-guid-cf8bc203-7fff-0fa3-3bf6-06f8665bddcf\"><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">Customer determines the duration of the Processing in accordance with the terms of this DPA.&nbsp;<\/span><\/span><\/p>\n<\/td>\n<\/tr>\n<tr style=\"height:0pt\">\n<td style=\"border-left:solid #000000 0.5pt;border-right:solid #000000 0.5pt;border-bottom:solid #000000 0.5pt;border-top:solid #000000 0.5pt;vertical-align:top;padding:0pt 5.4pt 0pt 5.4pt;overflow:hidden;overflow-wrap:break-word;\">\n<p dir=\"ltr\" style=\"line-height:1.2;margin-top:0pt;margin-bottom:0pt;\"><span id=\"docs-internal-guid-cf8bc203-7fff-0fa3-3bf6-06f8665bddcf\"><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">For transfers to (sub-) processors, also specify subject matter, nature and duration of the processing:<\/span><\/span><\/p>\n<\/td>\n<td style=\"border-left:solid #000000 0.5pt;border-right:solid #000000 0.5pt;border-bottom:solid #000000 0.5pt;border-top:solid #000000 0.5pt;vertical-align:top;padding:0pt 5.4pt 0pt 5.4pt;overflow:hidden;overflow-wrap:break-word;\">\n<p dir=\"ltr\" style=\"line-height:1.2;margin-top:0pt;margin-bottom:0pt;\"><span id=\"docs-internal-guid-cf8bc203-7fff-0fa3-3bf6-06f8665bddcf\"><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">As above.&nbsp;<\/span><\/span><\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table><\/div>\n<p>\n                    &nbsp;<\/p>\n<p dir=\"ltr\" style=\"line-height:1.2;margin-top:0pt;margin-bottom:8pt;\"><span id=\"docs-internal-guid-cf8bc203-7fff-0fa3-3bf6-06f8665bddcf\"><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">Annex 1(C): Competent supervisory authority<\/span><\/span><\/p>\n<p dir=\"ltr\" style=\"line-height:1.2;text-align: justify;margin-top:12pt;margin-bottom:0pt;\"><span id=\"docs-internal-guid-cf8bc203-7fff-0fa3-3bf6-06f8665bddcf\"><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">The Customer&#39;s competent supervisory authority will be determined in accordance with the GDPR, where applicable.&nbsp;<\/span><\/span><\/p>\n<p>&nbsp;<\/p>\n<p dir=\"ltr\" style=\"line-height:1.2;margin-top:0pt;margin-bottom:8pt;\"><span id=\"docs-internal-guid-cf8bc203-7fff-0fa3-3bf6-06f8665bddcf\"><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">Annex 2: Approved Sub-processors<\/span><\/span><\/p>\n<p dir=\"ltr\" style=\"line-height:1.2;text-align: justify;margin-top:12pt;margin-bottom:0pt;\"><span id=\"docs-internal-guid-cf8bc203-7fff-0fa3-3bf6-06f8665bddcf\"><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">The list of approved sub-processors of Bloomreach is available at <a href=\"https:\/\/www.bloomreach.com\/en\/legal\/subprocessors \">https:\/\/www.bloomreach.com\/en\/legal\/subprocessors <\/a><\/span><\/span><\/p>\n<p>&nbsp;<\/p>\n<p dir=\"ltr\" style=\"line-height:1.2;margin-top:0pt;margin-bottom:8pt;\"><span id=\"docs-internal-guid-cf8bc203-7fff-0fa3-3bf6-06f8665bddcf\"><span style=\"font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-weight: 700; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; \">Annex 3: Technical and organizational measures<\/span><\/span><\/p>\n<p dir=\"ltr\" style=\"line-height:1.2;margin-right: 6.75pt;margin-top:5pt;margin-bottom:6pt;\"><span style=\"font-size: 11pt; font-family: Arial,sans-serif;color:#000000;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;white-space:pre;white-space:pre-wrap;\">The technical and organizational measures implemented by Bloomreach (including any relevant certifications) to ensure an appropriate level of security taking into account the nature, scope, context and purposes of the processing, and the risks for the rights and freedoms of natural persons are as follows: &nbsp;&nbsp;<\/span><\/p>\n<p><\/p>\n<div align=\"left\" dir=\"ltr\" style=\"margin-left:-5.4pt;\">\n<table style=\"border:none;border-collapse:collapse;\">\n<tbody>\n<tr style=\"height:0pt;\">\n<td style=\"vertical-align:top;padding:0pt 5.4pt 0pt 5.4pt;overflow:hidden;overflow-wrap:break-word;\">\n<p dir=\"ltr\" style=\"line-height:1.25;text-align: justify;margin-top:0pt;margin-bottom:6pt;\"><span style=\"font-size: 11pt; font-family: Arial,sans-serif;color:#000000;background-color:transparent;font-weight:700;font-style:normal;font-variant:normal;text-decoration:underline;-webkit-text-decoration-skip:none;text-decoration-skip-ink:none;vertical-align:baseline;white-space:pre;white-space:pre-wrap;\">Security Measures &ndash; Bloomreach<\/span><\/p>\n<\/td>\n<\/tr>\n<tr style=\"height:0pt;\">\n<td style=\"vertical-align:top;padding:0pt 5.4pt 0pt 5.4pt;overflow:hidden;overflow-wrap:break-word;\">\n<p dir=\"ltr\" style=\"line-height:1.2;text-align: justify;margin-top:0pt;margin-bottom:6pt;\"><span style=\"font-size: 11pt; font-family: Arial,sans-serif;color:#000000;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;white-space:pre;white-space:pre-wrap;\">As of the Effective Date of the Agreement, Bloomreach maintains the technical and organisational security measures as described in this Annex 3 to the DPA. This Annex 3 is hereby incorporated into this DPA and shall form an inseparable part of hereof. &nbsp;Capitalized terms not otherwise defined shall have the meaning given to them in the DPA, MSA or the applicable Product Appendix.<\/span><\/p>\n<p dir=\"ltr\" style=\"line-height:1.25;text-align: justify;margin-top:0pt;margin-bottom:6pt;\"><span style=\"font-size: 11pt; font-family: Arial,sans-serif;color:#000000;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;white-space:pre;white-space:pre-wrap;\">For more details regarding our security measures, please refer to our SOC 2 (Type 1) Report (see sec. F below).&nbsp;<\/span><\/p>\n<\/td>\n<\/tr>\n<tr style=\"height:0pt;\">\n<td style=\"vertical-align:top;padding:0pt 5.4pt 0pt 5.4pt;overflow:hidden;overflow-wrap:break-word;\">\n<ol style=\"margin-top:0;margin-bottom:0;padding-inline-start:48px;\">\n<li aria-level=\"1\" dir=\"ltr\" style=\"list-style-type:upper-alpha;font-size: 11pt; font-family: Arial,sans-serif;color:#000000;background-color:transparent;font-weight:700;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;\">\n<p dir=\"ltr\" style=\"line-height:1.3800000000000001;text-align: justify;margin-top:0pt;margin-bottom:6pt;\"><span style=\"font-size: 11pt; font-family: Arial,sans-serif;color:#000000;background-color:transparent;font-weight:700;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;white-space:pre;white-space:pre-wrap;\">Access Control<\/span><\/p>\n<\/li>\n<\/ol>\n<\/td>\n<\/tr>\n<tr style=\"height:0pt;\">\n<td style=\"vertical-align:top;padding:0pt 5.4pt 0pt 5.4pt;overflow:hidden;overflow-wrap:break-word;\">\n<p dir=\"ltr\" style=\"line-height:1.2;text-align: justify;background-color:#ffffff;margin-top:0pt;margin-bottom:6pt;\"><span style=\"font-size: 11pt; font-family: Arial,sans-serif;color:#000000;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:underline;-webkit-text-decoration-skip:none;text-decoration-skip-ink:none;vertical-align:baseline;white-space:pre;white-space:pre-wrap;\">Physical Access Control<\/span><span style=\"font-size: 11pt; font-family: Arial,sans-serif;color:#000000;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;white-space:pre;white-space:pre-wrap;\">. &nbsp;Bloomreach takes measures to prevent unauthorized persons from entering the premises in which data processing systems are stored and with which personal data are processed.<\/span><\/p>\n<\/td>\n<\/tr>\n<tr style=\"height:0pt;\">\n<td style=\"vertical-align:top;padding:0pt 5.4pt 0pt 5.4pt;overflow:hidden;overflow-wrap:break-word;\">\n<p dir=\"ltr\" style=\"line-height:1.2;text-align: justify;background-color:#ffffff;margin-top:0pt;margin-bottom:6pt;\"><span style=\"font-size: 11pt; font-family: Arial,sans-serif;color:#000000;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:underline;-webkit-text-decoration-skip:none;text-decoration-skip-ink:none;vertical-align:baseline;white-space:pre;white-space:pre-wrap;\">Technical Access Control.<\/span><span style=\"font-size: 11pt; font-family: Arial,sans-serif;color:#000000;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;white-space:pre;white-space:pre-wrap;\">&nbsp;Bloomreach takes technical measures to prevent data processing systems from being used by unauthorized persons. These include authentication when accessing computers \/ systems using a user ID and password, as well as setting up firewalls.<\/span><\/p>\n<\/td>\n<\/tr>\n<tr style=\"height:0pt;\">\n<td style=\"vertical-align:top;padding:0pt 5.4pt 0pt 5.4pt;overflow:hidden;overflow-wrap:break-word;\">\n<p dir=\"ltr\" style=\"line-height:1.2;text-align: justify;background-color:#ffffff;margin-top:0pt;margin-bottom:6pt;\"><span style=\"font-size: 11pt; font-family: Arial,sans-serif;color:#000000;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:underline;-webkit-text-decoration-skip:none;text-decoration-skip-ink:none;vertical-align:baseline;white-space:pre;white-space:pre-wrap;\">Personnel Access Control.<\/span><span style=\"font-size: 11pt; font-family: Arial,sans-serif;color:#000000;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;white-space:pre;white-space:pre-wrap;\">&nbsp;Bloomreach ensures that only authorized personnel can access contents<\/span><span style=\"font-size: 11pt; font-family: Arial,sans-serif;color:#000000;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:underline;-webkit-text-decoration-skip:none;text-decoration-skip-ink:none;vertical-align:baseline;white-space:pre;white-space:pre-wrap;\">&nbsp;<\/span><span style=\"font-size: 11pt; font-family: Arial,sans-serif;color:#000000;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;white-space:pre;white-space:pre-wrap;\">and that personal data cannot be copied, changed or deleted without authorization during processing and use and after saving. When granting access rights to Bloomreach personnel working on the Customer&rsquo;s project, Bloomreach follows the principle of least privilege to ensure that Customer Data is accessed only by personnel that need the access in order to provide the Services as ordered by the Customer.&nbsp;<\/span><\/p>\n<\/td>\n<\/tr>\n<tr style=\"height:0pt;\">\n<td style=\"vertical-align:top;padding:0pt 5.4pt 0pt 5.4pt;overflow:hidden;overflow-wrap:break-word;\">\n<p dir=\"ltr\" style=\"line-height:1.2;text-align: justify;background-color:#ffffff;margin-top:0pt;margin-bottom:6pt;\"><span style=\"font-size: 11pt; font-family: Arial,sans-serif;color:#000000;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:underline;-webkit-text-decoration-skip:none;text-decoration-skip-ink:none;vertical-align:baseline;white-space:pre;white-space:pre-wrap;\">Penetration testing<\/span><span style=\"font-size: 11pt; font-family: Arial,sans-serif;color:#000000;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;white-space:pre;white-space:pre-wrap;\">. In order to prevent any unauthorised attacks to our platform, Bloomreach maintains contractual relationships with penetration testing service providers. Through regular penetration testing Bloomreach can identify and resolve foreseeable attacks and possible abuse scenarios and thus prevent them.<\/span><\/p>\n<\/td>\n<\/tr>\n<tr style=\"height:0pt;\">\n<td style=\"vertical-align:top;padding:0pt 5.4pt 0pt 5.4pt;overflow:hidden;overflow-wrap:break-word;\">\n<ol start=\"2\" style=\"margin-top:0;margin-bottom:0;padding-inline-start:48px;\">\n<li aria-level=\"1\" dir=\"ltr\" style=\"list-style-type:upper-alpha;font-size: 11pt; font-family: Arial,sans-serif;color:#000000;background-color:transparent;font-weight:700;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;\">\n<p dir=\"ltr\" style=\"line-height:1.3800000000000001;text-align: justify;margin-top:0pt;margin-bottom:6pt;\"><span style=\"font-size: 11pt; font-family: Arial,sans-serif;color:#000000;background-color:transparent;font-weight:700;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;white-space:pre;white-space:pre-wrap;\">Organisational Measures<\/span><\/p>\n<\/li>\n<\/ol>\n<\/td>\n<\/tr>\n<tr style=\"height:0pt;\">\n<td style=\"vertical-align:top;padding:0pt 5.4pt 0pt 5.4pt;overflow:hidden;overflow-wrap:break-word;\">\n<p dir=\"ltr\" style=\"line-height:1.2;text-align: justify;background-color:#ffffff;margin-top:0pt;margin-bottom:6pt;\"><span style=\"font-size: 11pt; font-family: Arial,sans-serif;color:#000000;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:underline;-webkit-text-decoration-skip:none;text-decoration-skip-ink:none;vertical-align:baseline;white-space:pre;white-space:pre-wrap;\">DPO.<\/span><span style=\"font-size: 11pt; font-family: Arial,sans-serif;color:#000000;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;white-space:pre;white-space:pre-wrap;\">&nbsp;Bloomreach has a designated Data Protection Officer (DPO), Chief Information Security Officer (CISO) and a team of Security Engineers, as well legal professionals, to monitor and ensure compliance with GDPR and local laws.&nbsp;<\/span><\/p>\n<\/td>\n<\/tr>\n<tr style=\"height:0pt;\">\n<td style=\"vertical-align:top;padding:0pt 5.4pt 0pt 5.4pt;overflow:hidden;overflow-wrap:break-word;\">\n<p dir=\"ltr\" style=\"line-height:1.2;text-align: justify;background-color:#ffffff;margin-top:0pt;margin-bottom:6pt;\"><span style=\"font-size: 11pt; font-family: Arial,sans-serif;color:#000000;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:underline;-webkit-text-decoration-skip:none;text-decoration-skip-ink:none;vertical-align:baseline;white-space:pre;white-space:pre-wrap;\">Personnel training.<\/span><span style=\"font-size: 11pt; font-family: Arial,sans-serif;color:#000000;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;white-space:pre;white-space:pre-wrap;\">&nbsp; Bloomreach organizes regular and obligatory whole company Security and GDPR trainings, as well as OWASP trainings to prevent Web Application Security Risks. During the onboarding process, the personnel are required to execute non-disclosure agreements. &nbsp;During the course of engagement with Bloomreach, all personnel follow guidelines to ensure confidentiality, professional and ethical standards necessary to guarantee effective Customer Data protection.&nbsp;<\/span><\/p>\n<\/td>\n<\/tr>\n<tr style=\"height:0pt;\">\n<td style=\"vertical-align:top;padding:0pt 5.4pt 0pt 5.4pt;overflow:hidden;overflow-wrap:break-word;\">\n<p dir=\"ltr\" style=\"line-height:1.2;text-align: justify;background-color:#ffffff;margin-top:0pt;margin-bottom:6pt;\"><span style=\"font-size: 11pt; font-family: Arial,sans-serif;color:#000000;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:underline;-webkit-text-decoration-skip:none;text-decoration-skip-ink:none;vertical-align:baseline;white-space:pre;white-space:pre-wrap;\">Remote Working Policy.<\/span><span style=\"font-size: 11pt; font-family: Arial,sans-serif;color:#000000;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;white-space:pre;white-space:pre-wrap;\">&nbsp;Bloomreach personnel must act in compliance with further measures such as the Remote working policy (Endpoint Security Management, mandatory VPN, etc.), device secure setup and security awareness, strong passwords policy, two factor authentication process, etc.&nbsp;<\/span><\/p>\n<\/td>\n<\/tr>\n<tr style=\"height:0pt;\">\n<td style=\"vertical-align:top;padding:0pt 5.4pt 0pt 5.4pt;overflow:hidden;overflow-wrap:break-word;\">\n<ol start=\"3\" style=\"margin-top:0;margin-bottom:0;padding-inline-start:48px;\">\n<li aria-level=\"1\" dir=\"ltr\" style=\"list-style-type:upper-alpha;font-size: 11pt; font-family: Arial,sans-serif;color:#000000;background-color:transparent;font-weight:700;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;\">\n<p dir=\"ltr\" style=\"line-height:1.3800000000000001;text-align: justify;margin-top:0pt;margin-bottom:6pt;\"><span style=\"font-size: 11pt; font-family: Arial,sans-serif;color:#000000;background-color:transparent;font-weight:700;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;white-space:pre;white-space:pre-wrap;\">Technical Measures<\/span><\/p>\n<\/li>\n<\/ol>\n<\/td>\n<\/tr>\n<tr style=\"height:0pt;\">\n<td style=\"vertical-align:top;padding:0pt 5.4pt 0pt 5.4pt;overflow:hidden;overflow-wrap:break-word;\">\n<p dir=\"ltr\" style=\"line-height:1.2;text-align: justify;background-color:#ffffff;margin-top:0pt;margin-bottom:6pt;\"><span style=\"font-size: 11pt; font-family: Arial,sans-serif;color:#000000;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:underline;-webkit-text-decoration-skip:none;text-decoration-skip-ink:none;vertical-align:baseline;white-space:pre;white-space:pre-wrap;\">Transfer Control<\/span><span style=\"font-size: 11pt; font-family: Arial,sans-serif;color:#000000;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;white-space:pre;white-space:pre-wrap;\">. Bloomreach prevents personal data from being read, copied, changed or deleted in an unauthorized way during electronic transmission, transport or storage on data media. This includes secure electronic transmission, VPN, firewalls, encryption, logging measures.&nbsp;<\/span><\/p>\n<\/td>\n<\/tr>\n<tr style=\"height:0pt;\">\n<td style=\"vertical-align:top;padding:0pt 5.4pt 0pt 5.4pt;overflow:hidden;overflow-wrap:break-word;\">\n<p dir=\"ltr\" style=\"line-height:1.2;text-align: justify;background-color:#ffffff;margin-top:0pt;margin-bottom:6pt;\"><span style=\"font-size: 11pt; font-family: Arial,sans-serif;color:#000000;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:underline;-webkit-text-decoration-skip:none;text-decoration-skip-ink:none;vertical-align:baseline;white-space:pre;white-space:pre-wrap;\">Input control<\/span><span style=\"font-size: 11pt; font-family: Arial,sans-serif;color:#000000;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;white-space:pre;white-space:pre-wrap;\">. Bloomreach ensures that it can be subsequently checked whether and by whom personal data have been entered, changed or deleted. This includes logging, user identification.<\/span><\/p>\n<\/td>\n<\/tr>\n<tr style=\"height:0pt;\">\n<td style=\"vertical-align:top;padding:0pt 5.4pt 0pt 5.4pt;overflow:hidden;overflow-wrap:break-word;\">\n<p dir=\"ltr\" style=\"line-height:1.2;text-align: justify;background-color:#ffffff;margin-top:0pt;margin-bottom:6pt;\"><span style=\"font-size: 11pt; font-family: Arial,sans-serif;color:#000000;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:underline;-webkit-text-decoration-skip:none;text-decoration-skip-ink:none;vertical-align:baseline;white-space:pre;white-space:pre-wrap;\">Availability control<\/span><span style=\"font-size: 11pt; font-family: Arial,sans-serif;color:#000000;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;white-space:pre;white-space:pre-wrap;\">. Bloomreach ensures that personal data is protected against accidental destruction or loss. This includes the usual fire protection measures and overvoltage protection, backup concept, virus protection, clean coding.<\/span><\/p>\n<\/td>\n<\/tr>\n<tr style=\"height:0pt;\">\n<td style=\"vertical-align:top;padding:0pt 5.4pt 0pt 5.4pt;overflow:hidden;overflow-wrap:break-word;\">\n<p dir=\"ltr\" style=\"line-height:1.2;text-align: justify;background-color:#ffffff;margin-top:0pt;margin-bottom:6pt;\"><span style=\"font-size: 11pt; font-family: Arial,sans-serif;color:#000000;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:underline;-webkit-text-decoration-skip:none;text-decoration-skip-ink:none;vertical-align:baseline;white-space:pre;white-space:pre-wrap;\">Separation control<\/span><span style=\"font-size: 11pt; font-family: Arial,sans-serif;color:#000000;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;white-space:pre;white-space:pre-wrap;\">. Bloomreach ensures that personal data collected for different purposes is processed separately. This includes separate customer accounts, separate databases, encryption methods.<\/span><\/p>\n<\/td>\n<\/tr>\n<tr style=\"height:45.75pt;\">\n<td style=\"vertical-align:top;padding:0pt 5.4pt 0pt 5.4pt;overflow:hidden;overflow-wrap:break-word;\">\n<p dir=\"ltr\" style=\"line-height:1.2;text-align: justify;margin-top:0pt;margin-bottom:6pt;\"><span style=\"font-size: 11pt; font-family: Arial,sans-serif;color:#000000;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:underline;-webkit-text-decoration-skip:none;text-decoration-skip-ink:none;vertical-align:baseline;white-space:pre;white-space:pre-wrap;\">Data Encryption<\/span><span style=\"font-size: 11pt; font-family: Arial,sans-serif;color:#000000;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;white-space:pre;white-space:pre-wrap;\">. There are several layers of encryption of data. Data is encrypted in transit.&nbsp;<\/span><\/p>\n<\/td>\n<\/tr>\n<tr style=\"height:0pt;\">\n<td style=\"vertical-align:top;padding:0pt 5.4pt 0pt 5.4pt;overflow:hidden;overflow-wrap:break-word;\">\n<p dir=\"ltr\" style=\"line-height:1.2;text-align: justify;margin-top:0pt;margin-bottom:6pt;\"><span style=\"font-size: 11pt; font-family: Arial,sans-serif;color:#000000;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:underline;-webkit-text-decoration-skip:none;text-decoration-skip-ink:none;vertical-align:baseline;white-space:pre;white-space:pre-wrap;\">TLS.<\/span><span style=\"font-size: 11pt; font-family: Arial,sans-serif;color:#000000;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;white-space:pre;white-space:pre-wrap;\">&nbsp;Transport Layer Security (TLS) security protocol is used for communication within the app and web tracking.<\/span><\/p>\n<\/td>\n<\/tr>\n<tr style=\"height:0pt;\">\n<td style=\"vertical-align:top;padding:0pt 5.4pt 0pt 5.4pt;overflow:hidden;overflow-wrap:break-word;\">\n<p dir=\"ltr\" style=\"line-height:1.2;text-align: justify;margin-top:0pt;margin-bottom:6pt;\"><span style=\"font-size: 11pt; font-family: Arial,sans-serif;color:#000000;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:underline;-webkit-text-decoration-skip:none;text-decoration-skip-ink:none;vertical-align:baseline;white-space:pre;white-space:pre-wrap;\">Additional Technical Measures.<\/span><span style=\"font-size: 11pt; font-family: Arial,sans-serif;color:#000000;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;white-space:pre;white-space:pre-wrap;\">&nbsp;Firewalls, logging, malware protection, security scans and other control mechanisms are in place to provide further technical security.&nbsp;<\/span><\/p>\n<\/td>\n<\/tr>\n<tr style=\"height:0pt;\">\n<td style=\"vertical-align:top;padding:0pt 5.4pt 0pt 5.4pt;overflow:hidden;overflow-wrap:break-word;\"><\/td>\n<\/tr>\n<tr style=\"height:0pt;\">\n<td style=\"vertical-align:top;padding:0pt 5.4pt 0pt 5.4pt;overflow:hidden;overflow-wrap:break-word;\">\n<ol start=\"4\" style=\"margin-top:0;margin-bottom:0;padding-inline-start:48px;\">\n<li aria-level=\"1\" dir=\"ltr\" style=\"list-style-type:upper-alpha;font-size: 11pt; font-family: Arial,sans-serif;color:#000000;background-color:transparent;font-weight:700;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;\">\n<p dir=\"ltr\" style=\"line-height:1.3800000000000001;text-align: justify;margin-top:0pt;margin-bottom:6pt;\"><span style=\"font-size: 11pt; font-family: Arial,sans-serif;color:#000000;background-color:transparent;font-weight:700;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;white-space:pre;white-space:pre-wrap;\">Security Development practices&nbsp;<\/span><\/p>\n<\/li>\n<\/ol>\n<\/td>\n<\/tr>\n<tr style=\"height:0pt;\">\n<td style=\"vertical-align:top;padding:0pt 5.4pt 0pt 5.4pt;overflow:hidden;overflow-wrap:break-word;\">\n<p dir=\"ltr\" style=\"line-height:1.2;text-align: justify;background-color:#ffffff;margin-top:0pt;margin-bottom:6pt;\"><span style=\"font-size: 11pt; font-family: Arial,sans-serif;color:#000000;background-color:transparent;font-weight:700;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;white-space:pre;white-space:pre-wrap;\">Bloomreach<\/span><span style=\"font-size: 11pt; font-family: Arial,sans-serif;color:#000000;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;white-space:pre;white-space:pre-wrap;\">&nbsp;has the further following practices in place to ensure the security of the application:&nbsp;<\/span><\/p>\n<ul style=\"margin-top:0;margin-bottom:0;padding-inline-start:48px;\">\n<li aria-level=\"1\" dir=\"ltr\" style=\"list-style-type:disc;font-size: 11pt; font-family: Arial,sans-serif;color:#000000;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;\">\n<p dir=\"ltr\" style=\"line-height:1.2;text-align: justify;background-color:#ffffff;margin-top:0pt;margin-bottom:0pt;padding:0pt 0pt 6pt 0pt;\"><span style=\"font-size: 11pt; font-family: Arial,sans-serif;color:#000000;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;white-space:pre;white-space:pre-wrap;\">Clean coding and least privilege access granting for Bloomreach IT developers.<\/span><\/p>\n<\/li>\n<li aria-level=\"1\" dir=\"ltr\" style=\"list-style-type:disc;font-size: 11pt; font-family: Arial,sans-serif;color:#000000;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;\">\n<p dir=\"ltr\" style=\"line-height:1.2;text-align: justify;background-color:#ffffff;margin-top:0pt;margin-bottom:0pt;padding:0pt 0pt 6pt 0pt;\"><span style=\"font-size: 11pt; font-family: Arial,sans-serif;color:#000000;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;white-space:pre;white-space:pre-wrap;\">Monitoring traffic&nbsp;&ndash; Internal network traffic is regularly checked for any suspicious behaviour.<\/span><\/p>\n<\/li>\n<li aria-level=\"1\" dir=\"ltr\" style=\"list-style-type:disc;font-size: 11pt; font-family: Arial,sans-serif;color:#000000;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;\">\n<p dir=\"ltr\" style=\"line-height:1.2;text-align: justify;background-color:#ffffff;margin-top:0pt;margin-bottom:0pt;padding:0pt 0pt 6pt 0pt;\"><span style=\"font-size: 11pt; font-family: Arial,sans-serif;color:#000000;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;white-space:pre;white-space:pre-wrap;\">Vulnerability Management and penetration tests &ndash; Bloomreach conducts regular web scans and scans for potential threats.<\/span><\/p>\n<\/li>\n<li aria-level=\"1\" dir=\"ltr\" style=\"list-style-type:disc;font-size: 11pt; font-family: Arial,sans-serif;color:#000000;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;\">\n<p dir=\"ltr\" style=\"line-height:1.2;text-align: justify;background-color:#ffffff;margin-top:0pt;margin-bottom:0pt;padding:0pt 0pt 6pt 0pt;\"><span style=\"font-size: 11pt; font-family: Arial,sans-serif;color:#000000;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;white-space:pre;white-space:pre-wrap;\">Incident Management &#8211; Bloomreach has a well-defined incident management process for security events, including reporting, prioritization based on urgency, escalation and mitigation.<\/span><\/p>\n<\/li>\n<li aria-level=\"1\" dir=\"ltr\" style=\"list-style-type:disc;font-size: 11pt; font-family: Arial,sans-serif;color:#000000;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;\">\n<p dir=\"ltr\" style=\"line-height:1.2;text-align: justify;background-color:#ffffff;margin-top:0pt;margin-bottom:0pt;padding:0pt 0pt 6pt 0pt;\"><span style=\"font-size: 11pt; font-family: Arial,sans-serif;color:#000000;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;white-space:pre;white-space:pre-wrap;\">Business Continuity &ndash; Bloomreach regularly reviews all business-critical functions.&nbsp;<\/span><\/p>\n<\/li>\n<li aria-level=\"1\" dir=\"ltr\" style=\"list-style-type:disc;font-size: 11pt; font-family: Arial,sans-serif;color:#000000;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;\">\n<p dir=\"ltr\" style=\"line-height:1.2;text-align: justify;background-color:#ffffff;margin-top:0pt;margin-bottom:6pt;\"><span style=\"font-size: 11pt; font-family: Arial,sans-serif;color:#000000;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;white-space:pre;white-space:pre-wrap;\">Quality assurance &ndash; Bloomreach tests all new features before implementing them to the application.<\/span><\/p>\n<\/li>\n<\/ul>\n<\/td>\n<\/tr>\n<tr style=\"height:0pt;\">\n<td style=\"vertical-align:top;padding:0pt 5.4pt 0pt 5.4pt;overflow:hidden;overflow-wrap:break-word;\">\n<ol start=\"5\" style=\"margin-top:0;margin-bottom:0;padding-inline-start:48px;\">\n<li aria-level=\"1\" dir=\"ltr\" style=\"list-style-type:upper-alpha;font-size: 11pt; font-family: Arial,sans-serif;color:#000000;background-color:transparent;font-weight:700;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;\">\n<p dir=\"ltr\" style=\"line-height:1.3800000000000001;text-align: justify;margin-top:0pt;margin-bottom:6pt;\"><span style=\"font-size: 11pt; font-family: Arial,sans-serif;color:#000000;background-color:transparent;font-weight:700;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;white-space:pre;white-space:pre-wrap;\">Further measures to protect Customer Data<\/span><\/p>\n<\/li>\n<\/ol>\n<\/td>\n<\/tr>\n<tr style=\"height:0pt;\">\n<td style=\"vertical-align:top;padding:0pt 5.4pt 0pt 5.4pt;overflow:hidden;overflow-wrap:break-word;\">\n<p dir=\"ltr\" style=\"line-height:1.2;text-align: justify;margin-top:0pt;margin-bottom:6pt;\"><span style=\"font-size: 11pt; font-family: Arial,sans-serif;color:#000000;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:underline;-webkit-text-decoration-skip:none;text-decoration-skip-ink:none;vertical-align:baseline;white-space:pre;white-space:pre-wrap;\">Infrastructure<\/span><span style=\"font-size: 11pt; font-family: Arial,sans-serif;color:#000000;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;white-space:pre;white-space:pre-wrap;\">. Bloomreach relies upon acknowledged hosting providers in the field, that (i) enable a multi-tenant, geographically distributed environment and a high availability infrastructure, (ii) comply with all data protection obligations as stipulated in applicable Data Protection Legislation.&nbsp;<\/span><\/p>\n<\/td>\n<\/tr>\n<tr style=\"height:0pt;\">\n<td style=\"vertical-align:top;padding:0pt 5.4pt 0pt 5.4pt;overflow:hidden;overflow-wrap:break-word;\">\n<p dir=\"ltr\" style=\"line-height:1.2;text-align: justify;background-color:#ffffff;margin-top:0pt;margin-bottom:6pt;\"><span style=\"font-size: 11pt; font-family: Arial,sans-serif;color:#000000;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:underline;-webkit-text-decoration-skip:none;text-decoration-skip-ink:none;vertical-align:baseline;white-space:pre;white-space:pre-wrap;\">Control of Processors<\/span><span style=\"font-size: 11pt; font-family: Arial,sans-serif;color:#000000;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;white-space:pre;white-space:pre-wrap;\">. Bloomreach ensures that personal data processed by Processors are processed in accordance with the instructions of Bloomreach and its customers. This includes control rights and data processing contracts according to the GDPR.<\/span><\/p>\n<\/td>\n<\/tr>\n<tr style=\"height:0pt;\">\n<td style=\"vertical-align:top;padding:0pt 5.4pt 0pt 5.4pt;overflow:hidden;overflow-wrap:break-word;\">\n<p dir=\"ltr\" style=\"line-height:1.2;text-align: justify;background-color:#ffffff;margin-top:0pt;margin-bottom:6pt;\"><span style=\"font-size: 11pt; font-family: Arial,sans-serif;color:#000000;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:underline;-webkit-text-decoration-skip:none;text-decoration-skip-ink:none;vertical-align:baseline;white-space:pre;white-space:pre-wrap;\">External Audit<\/span><span style=\"font-size: 11pt; font-family: Arial,sans-serif;color:#000000;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;white-space:pre;white-space:pre-wrap;\">. Bloomreach is subject to external annual audit by an independent third-party licensed auditor to test, evaluate and confirm that the security measures are up-to-date, effective and functional.&nbsp;<\/span><\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table><\/div>\n<p dir=\"ltr\" style=\"line-height:1.2;text-align: justify;margin-top:0pt;margin-bottom:10pt;\"><\/p>\n<div align=\"left\" dir=\"ltr\" style=\"margin-left:-5.4pt;\">\n<table style=\"border:none;border-collapse:collapse;\">\n<tbody>\n<tr style=\"height:0pt;\">\n<td style=\"vertical-align:top;padding:0pt 5.4pt 0pt 5.4pt;overflow:hidden;overflow-wrap:break-word;\">\n<ol start=\"6\" style=\"margin-top:0;margin-bottom:0;padding-inline-start:48px;\">\n<li aria-level=\"1\" dir=\"ltr\" style=\"list-style-type:upper-alpha;font-size: 11pt; font-family: Arial,sans-serif;color:#000000;background-color:transparent;font-weight:700;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;\">\n<p dir=\"ltr\" style=\"line-height:1.3800000000000001;text-align: justify;margin-top:0pt;margin-bottom:6pt;\"><span style=\"font-size: 11pt; font-family: Arial,sans-serif;color:#000000;background-color:transparent;font-weight:700;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;white-space:pre;white-space:pre-wrap;\">Certification<\/span><\/p>\n<\/li>\n<\/ol>\n<\/td>\n<\/tr>\n<tr style=\"height:0pt;\">\n<td style=\"vertical-align:top;padding:0pt 5.4pt 0pt 5.4pt;overflow:hidden;overflow-wrap:break-word;\">\n<p dir=\"ltr\" style=\"line-height:1.2;text-align: justify;margin-top:0pt;margin-bottom:6pt;\"><span style=\"font-size: 11pt; font-family: Arial,sans-serif;color:#000000;background-color:transparent;font-weight:700;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;white-space:pre;white-space:pre-wrap;\">Bloomreach<\/span><span style=\"font-size: 11pt; font-family: Arial,sans-serif;color:#000000;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;white-space:pre;white-space:pre-wrap;\">&nbsp;currently maintains the following certifications:&nbsp;<\/span><\/p>\n<ul style=\"margin-top:0;margin-bottom:0;padding-inline-start:48px;\">\n<li aria-level=\"1\" dir=\"ltr\" style=\"list-style-type:disc;font-size: 11pt; font-family: Arial,sans-serif;color:#1c1733;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;\">\n<p dir=\"ltr\" style=\"line-height:1.2;text-align: justify;margin-top:0pt;margin-bottom:6pt;\"><a href=\"https:\/\/br-cms.bloomreach.com\/site\/binaries\/content\/assets\/assets\/certificates\/gdpr-3101.pdf\" style=\"text-decoration:none;\" target=\"_blank\" rel=\"noopener\"><span style=\"font-size: 11pt; font-family: Arial,sans-serif;color:#1bb6dd;background-color:#ffffff;font-weight:400;font-style:normal;font-variant:normal;text-decoration:underline;-webkit-text-decoration-skip:none;text-decoration-skip-ink:none;vertical-align:baseline;white-space:pre;white-space:pre-wrap;\">GDPR 3101<\/span><\/a><\/p>\n<\/li>\n<li aria-level=\"1\" dir=\"ltr\" style=\"list-style-type:disc;font-size: 11pt; font-family: Arial,sans-serif;color:#1c1733;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;\">\n<p dir=\"ltr\" style=\"line-height:1.2;text-align: justify;margin-top:0pt;margin-bottom:6pt;\"><a href=\"https:\/\/br-cms.bloomreach.com\/site\/binaries\/content\/assets\/assets\/certificates\/iso-9001_2015.pdf\" style=\"text-decoration:none;\" target=\"_blank\" rel=\"noopener\"><span style=\"font-size: 11pt; font-family: Arial,sans-serif;color:#1bb6dd;background-color:#ffffff;font-weight:400;font-style:normal;font-variant:normal;text-decoration:underline;-webkit-text-decoration-skip:none;text-decoration-skip-ink:none;vertical-align:baseline;white-space:pre;white-space:pre-wrap;\">ISO 9001:2015<\/span><\/a><\/p>\n<\/li>\n<li aria-level=\"1\" dir=\"ltr\" style=\"list-style-type:disc;font-size: 11pt; font-family: Arial,sans-serif;color:#1c1733;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;\">\n<p dir=\"ltr\" style=\"line-height:1.2;text-align: justify;margin-top:0pt;margin-bottom:6pt;\"><a href=\"https:\/\/br-cms.bloomreach.com\/site\/binaries\/content\/assets\/assets\/certificates\/iso_iec-27001_2013.pdf\" style=\"text-decoration:none;\" target=\"_blank\" rel=\"noopener\"><span style=\"font-size: 11pt; font-family: Arial,sans-serif;color:#1bb6dd;background-color:#ffffff;font-weight:400;font-style:normal;font-variant:normal;text-decoration:underline;-webkit-text-decoration-skip:none;text-decoration-skip-ink:none;vertical-align:baseline;white-space:pre;white-space:pre-wrap;\">ISO 27001:2013<\/span><\/a><\/p>\n<\/li>\n<li aria-level=\"1\" dir=\"ltr\" style=\"list-style-type:disc;font-size: 11pt; font-family: Arial,sans-serif;color:#1c1733;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;\">\n<p dir=\"ltr\" style=\"line-height:1.2;text-align: justify;margin-top:0pt;margin-bottom:6pt;\"><a href=\"https:\/\/br-cms.bloomreach.com\/site\/binaries\/content\/assets\/assets\/certificates\/iso_iec-27017_2015.pdf\" style=\"text-decoration:none;\" target=\"_blank\" rel=\"noopener\"><span style=\"font-size: 11pt; font-family: Arial,sans-serif;color:#1bb6dd;background-color:#ffffff;font-weight:400;font-style:normal;font-variant:normal;text-decoration:underline;-webkit-text-decoration-skip:none;text-decoration-skip-ink:none;vertical-align:baseline;white-space:pre;white-space:pre-wrap;\">ISO 27017:2015<\/span><\/a><\/p>\n<\/li>\n<li aria-level=\"1\" dir=\"ltr\" style=\"list-style-type:disc;font-size: 11pt; font-family: Arial,sans-serif;color:#1c1733;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;\">\n<p dir=\"ltr\" style=\"line-height:1.2;text-align: justify;margin-top:0pt;margin-bottom:6pt;\"><a href=\"https:\/\/br-cms.bloomreach.com\/site\/binaries\/content\/assets\/assets\/certificates\/iso_iec-27018_2019.pdf\" style=\"text-decoration:none;\" target=\"_blank\" rel=\"noopener\"><span style=\"font-size: 11pt; font-family: Arial,sans-serif;color:#1bb6dd;background-color:#ffffff;font-weight:400;font-style:normal;font-variant:normal;text-decoration:underline;-webkit-text-decoration-skip:none;text-decoration-skip-ink:none;vertical-align:baseline;white-space:pre;white-space:pre-wrap;\">ISO 27018:2019<\/span><\/a><\/p>\n<\/li>\n<li aria-level=\"1\" dir=\"ltr\" style=\"list-style-type:disc;font-size: 11pt; font-family: Arial,sans-serif;color:#1c1733;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;\">\n<p dir=\"ltr\" style=\"line-height:1.2;text-align: justify;margin-top:0pt;margin-bottom:6pt;\"><a href=\"https:\/\/br-cms.bloomreach.com\/site\/binaries\/content\/assets\/assets\/certificates\/iso-22301_2019.pdf\" style=\"text-decoration:none;\" target=\"_blank\" rel=\"noopener\"><span style=\"font-size: 11pt; font-family: Arial,sans-serif;color:#1bb6dd;background-color:#ffffff;font-weight:400;font-style:normal;font-variant:normal;text-decoration:underline;-webkit-text-decoration-skip:none;text-decoration-skip-ink:none;vertical-align:baseline;white-space:pre;white-space:pre-wrap;\">ISO 22301:2019<\/span><\/a><\/p>\n<\/li>\n<\/ul>\n<p dir=\"ltr\" style=\"line-height:1.2;text-align: justify;margin-top:0pt;margin-bottom:6pt;\"><span style=\"font-size: 11pt; font-family: Arial,sans-serif;color:#000000;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;white-space:pre;white-space:pre-wrap;\">More information available at:<\/span><\/p>\n<p dir=\"ltr\" style=\"line-height:1.2;text-align: justify;margin-top:0pt;margin-bottom:6pt;\"><span style=\"font-size: 11pt; font-family: Arial,sans-serif;color:#000000;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;white-space:pre;white-space:pre-wrap;\">&nbsp;https:\/\/www.bloomreach.com\/en\/legal\/security<\/span><\/p>\n<\/td>\n<\/tr>\n<tr style=\"height:0pt;\">\n<td style=\"vertical-align:top;padding:0pt 5.4pt 0pt 5.4pt;overflow:hidden;overflow-wrap:break-word;\">\n<p dir=\"ltr\" style=\"line-height:1.2;text-align: justify;margin-top:0pt;margin-bottom:6pt;\"><span style=\"font-size: 11pt; font-family: Arial,sans-serif;color:#1c1733;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;white-space:pre;white-space:pre-wrap;\">Bloomreach<\/span><span style=\"font-size: 11pt; font-family: Arial,sans-serif;color:#000000;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;white-space:pre;white-space:pre-wrap;\">&nbsp;also holds a SOC 2 (Type 1) Report. This contains specifics pertaining to security measures and can be provided under a non-disclosure agreement. &nbsp; &nbsp; &nbsp;<\/span><\/p>\n<\/td>\n<\/tr>\n<tr style=\"height:53.508544921875pt;\">\n<td style=\"vertical-align:top;padding:0pt 5.4pt 0pt 5.4pt;overflow:hidden;overflow-wrap:break-word;\">\n<p dir=\"ltr\" style=\"line-height:1.3800000000000001;text-align: justify;margin-top:0pt;margin-bottom:6pt;\"><span style=\"font-size: 11pt; font-family: Arial,sans-serif;color:#000000;background-color:transparent;font-weight:400;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;white-space:pre;white-space:pre-wrap;\">Bloomreach reserves the right to replace any security measures with an equivalent or enhanced alternative at any time during the Term of the Agreement that ensure equal data security and measures in compliance with state of the art security standards applicable in the field. &nbsp;<\/span><\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table><\/div>\n<p>                <!--content end-->\n            <\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/section>\n","protected":false},"parent":0,"menu_order":0,"template":"","class_list":["post-2215","legal","type-legal","status-publish","hentry"],"acf":[],"_links":{"self":[{"href":"https:\/\/www.bloomreach.com\/en\/wp-json\/wp\/v2\/legal\/2215","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.bloomreach.com\/en\/wp-json\/wp\/v2\/legal"}],"about":[{"href":"https:\/\/www.bloomreach.com\/en\/wp-json\/wp\/v2\/types\/legal"}],"version-history":[{"count":0,"href":"https:\/\/www.bloomreach.com\/en\/wp-json\/wp\/v2\/legal\/2215\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.bloomreach.com\/en\/wp-json\/wp\/v2\/media?parent=2215"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}