Data Processing Addendum

Last updated: September 25, 2026

THIS DATA PROCESSING ADDENDUM (“DPA”) is entered into as of the Addendum Effective Date by and between: (1) NISOS HOLDINGS INC., a Delaware corporation with its principal business address at 2101 Arlington Blvd., Suite 304, Arlington, VA 22201 (“Nisos”); and (2) the entity identified as the client in the applicable Ordering Document (“Client”), together the “Parties” and each a “Party”. This DPA is incorporated into and forms part of the MSA (as defined below).

1. DEFINITIONS

In this DPA, the terms “business,” “business purpose,” “commercial purpose,” “consumer,” “sell,” “share” and “service provider” shall have the respective meanings given thereto in the CCPA; and “personal information” shall mean Client Personal Data that constitutes “personal information” as defined in and that is subject to the CCPA and/or the US State Privacy Laws (as applicable).

Unless otherwise defined in this DPA, all capitalized terms in this DPA shall have the meaning given to them in the MSA.

a. Addendum Effective Date: the date on which Client first executes an Ordering Document that incorporates or references the MSA, or, if earlier, the date on which Client first accesses or uses the Services.

b. Applicable Data Protection Laws: the privacy, data protection and data security laws and regulations of any jurisdiction applicable to the Processing of Client Personal Data under the MSA, including, without limitation, GDPR, the CCPA and US State Privacy Laws (each as and where applicable).

c. CCPA: the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 (“CPRA”), and any binding regulations promulgated thereunder, including regulations issued by the California Privacy Protection Agency.

d. Controller: the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data.

e. Client Personal Data: any Personal Data provided by or on behalf of Client and Processed by Nisos or its Sub-processor on behalf of Client to perform the Services under the MSA, including any data that constitutes “Client PII” as defined in the MSA. For the avoidance of doubt, Client Personal Data does not include Personal Data that Nisos collects or obtains independently from publicly available, licensed, or other third-party sources, which constitutes Service Data.

f. Data Source Provider: a Sub-processor that makes available a proprietary, licensed, commercial or public-records dataset, search service, or data enrichment or verification service that Nisos queries in the course of performing the Services, and whose Processing of Client Personal Data is limited to receiving query terms submitted by or on behalf of Nisos and returning results to Nisos. Data Source Providers may include, without limitation, providers of open-source intelligence, public records, identity resolution, breach and credential exposure data, social media and web content, corporate and financial records, communications and telephony data, geolocation data, and network and infrastructure data.

g. Data Subject Request: the exercise by a Data Subject of its rights in accordance with Applicable Data Protection Laws in respect of Client Personal Data and the Processing thereof.

h. Data Subject: the identified or identifiable natural person to whom Client Personal Data relates.

i. Data Transfer Mechanism: in respect of: (i) any EU Restricted Transfer, the EU SCCs; (ii) any UK Restricted Transfer, the UK Addendum; and (iii) any Swiss Restricted Transfer, the EU SCCs as modified by the Swiss Schedule.

j. EEA: the European Economic Area.

k. EU SCCs: the standard contractual clauses approved by the European Commission pursuant to Commission Implementing Decision (EU) 2021/914 of 4 June 2021 applicable to an EU Restricted Transfer (as determined in accordance with Paragraph 6(b) of Annex 1 (European Annex)), incorporated by reference into this DPA as set out in Attachment 2 of Annex 1 (European Annex). References to “Modules” shall refer to modules of the EU SCCs.

l. FADP: the Swiss Federal Act on Data Protection of 25 September 2020 (as amended, and including any implementing ordinances), or, where the context requires, its predecessor legislation of 19 June 1992, in each case as and where applicable to the Processing of Client Personal Data.

m. GDPR: as and where applicable to Processing concerned: (i) the General Data Protection Regulation (Regulation (EU) 2016/679) (“EU GDPR”); and/or (ii) the EU GDPR as it forms part of UK law by virtue of section 3 of the European Union (Withdrawal) Act 2018 (as amended, including by the Data Protection, Privacy and Electronic Communications (Amendments etc.) (EU Exit) Regulations 2019) (“UK GDPR”), including, in each case (i) and (ii) any applicable national implementing or supplementary legislation (e.g., the UK Data Protection Act 2018), and any successor, amendment or re-enactment, to or of the foregoing. References to “Articles” and “Chapters” of, and other relevant defined terms in, the GDPR shall be construed accordingly.

n. MSA: the agreement governing Client’s use of the Services, whether in the form of (i) Nisos’ standard terms of service as made available at https://nisos.com/nisos-services-terms-conditions/ (as updated from time to time) or (ii) a separately executed master services agreement between the Parties. For the avoidance of doubt, the MSA is the governing agreement between the Parties and is separate from any Ordering Documents entered into thereunder.

o. Nisos’ Privacy Policy: Nisos’ privacy policy as made available at https://www.nisos.com/privacy-policy/, as updated from time to time, pursuant to the MSA.

p. Ordering Document: any document executed by both Parties that specifies details regarding the Services to be provided under the MSA, including but not limited to order forms and statements of work. For the avoidance of doubt, each Ordering Document is a separate document from, and is governed by, the MSA.

q. Personal Data Breach: a breach of Nisos’ security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Client Personal Data in Nisos’ possession, custody or control. For clarity, Personal Data Breach does not include unsuccessful attempts or activities that do not compromise the security of Client Personal Data (such as unsuccessful log-in attempts, pings, port scans, denial of service attacks, or other network attacks on firewalls or networked systems).

r. Personal Data: “personal data,” “personal information,” “personally identifiable information” or similar term defined in Applicable Data Protection Laws.

s. Personnel: a person’s employees, agents, consultants or contractors.

t. Process: any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.

u. Processor: a natural or legal person, public authority, agency or other body which Processes Personal Data on behalf of the Controller.

v. Restricted Data: has the meaning given to it in Section 9(c).

w. Restricted Transfer: the disclosure, grant of access or other transfer of Client Personal Data to any person located in: (i) in the context of the EEA, any country or territory outside the EEA which does not benefit from an adequacy decision from the European Commission (an “EU Restricted Transfer”); (ii) in the context of the UK, any country or territory outside the UK, which does not benefit from an adequacy decision from the UK Government (a “UK Restricted Transfer”); and (iii) in the context of Switzerland, any country or territory outside Switzerland which does not benefit from an adequacy decision recognized under the FADP (a “Swiss Restricted Transfer”), which would be prohibited without a legal basis under the FADP.

x. Service Data: (i) any data relating to the use, support and/or operation of the Services, which is collected directly by Nisos from and/or about users of the Services and/or Client’s use of the Services for use for its own purposes (certain of which may constitute Personal Data), including learnings, methodologies, analytical techniques, and contextual knowledge retained by Nisos in de-identified form pursuant to Section 2.8 of the MSA (Retained Knowledge and Service Continuity); and (ii) any Personal Data that Nisos collects or obtains independently from publicly available, licensed, or other third-party sources, including in the course of performing the Services.

y. Services: those services and activities to be supplied to or carried out by or on behalf of Nisos for Client pursuant to the MSA.

z. Sub-processor: any third party appointed by or on behalf of Nisos to Process Client Personal Data, which may identify Data Source Providers by category in accordance with Paragraph 2(g) of Annex 1 (European Annex).

aa. Sub-processor List: the list of Sub-processors located at https://trust.nisos.com.

bb. Swiss Schedule: the schedule addressing FADP requirements applicable to Swiss Restricted Transfers, incorporated by reference into this DPA as set out in Attachment 4 of Annex 1 (European Annex).

cc. Supervisory Authority: (i) in the context of the EEA and the EU GDPR, shall have the meaning given to that term in the EU GDPR; (ii) in the context of the UK and the UK GDPR, means the UK Information Commissioner’s Office; and (iii) in the context of Switzerland and the FADP, means the Swiss Federal Data Protection and Information Commissioner (“FDPIC”).

dd. UK Addendum: the template addendum B1.0 issued by the ICO under s119A(1) of the Data Protection Act 2018, in force from 21 March 2022, incorporated by reference into this DPA as set out in Attachment 3 of Annex 1 (European Annex).

ee. US State Privacy Laws: as and where applicable to the Processing of Client Personal Data, the comprehensive state privacy and data protection laws of the United States (other than the CCPA), including, without limitation, the Virginia Consumer Data Protection Act, the Colorado Privacy Act, the Connecticut Data Privacy Act, the Texas Data Privacy and Security Act, the Oregon Consumer Privacy Act, and any similar comprehensive state privacy law that becomes effective during the term of the MSA, in each case together with any binding regulations promulgated thereunder and any successor, amendment or re-enactment thereof.

2. SCOPE OF THIS DATA PROCESSING ADDENDUM

a. The front-end of this DPA applies generally to Nisos’ Processing of Client Personal Data under the MSA.

b. Annex 1 (European Annex) to this DPA applies only if and to the extent Nisos’ Processing of Client Personal Data under the MSA is subject to the GDPR or the FADP.

c. Annex 2 (US Privacy Annex) to this DPA applies if and to the extent Nisos’ Processing of Client Personal Data under the MSA is subject to the CCPA with respect to which Client is a “business” (as defined in the CCPA) and/or any US State Privacy Laws.

3. PROCESSING OF CLIENT PERSONAL DATA

Nisos as a Processor

a. Subject to Sections 3(c) through 3(e), Nisos shall not Process Client Personal Data other than on Client’s instructions or as required by applicable laws.

b. Client instructs Nisos to Process Client Personal Data as necessary to provide the Services to Client under and in accordance with the MSA.

Nisos as a Controller

c. Client acknowledges that Nisos may Process Service Data for its own purposes, such as:

– for accounting, tax, billing, audit, and compliance purposes.

– to provide, improve, develop, optimize and maintain the Services.

– to investigate fraud, spam, wrongful or unlawful use of the Services.

– to create, and derive from Processing under this DPA, de-identified, anonymized and/or aggregated data that does not identify Client or any Data Subject.

– as otherwise permitted or required by applicable law.

d. In respect of any such Processing described in Section 3(c), Nisos:
– acts as an independent Controller.

– shall comply with Applicable Data Protection Laws (if and as applicable in the context).

– shall Process such Service Data as described in Nisos’ Privacy Policy.

– where possible, shall apply technical and organizational safeguards to any relevant Personal Data that are no less protective than the Security Measures.

e. To the extent Nisos uses artificial intelligence or automated processing tools in the performance of the Services, Nisos shall:
– not use Client Personal Data to train, fine-tune, or improve any AI or machine learning model, except in de-identified and aggregated form consistent with Section 3(c).

– ensure that any third-party AI systems or APIs used to Process Client Personal Data are treated as Sub-processors subject to the requirements of this DPA.

– upon Client’s written request, provide reasonable information regarding the use of automated processing tools in connection with Client Personal Data, including whether such tools involve automated decision-making or profiling within the meaning of Article 22 of the GDPR.

– not make any decision based solely on automated Processing of Client Personal Data that produces legal effects concerning, or similarly significantly affects, a Data Subject, unless Client has provided express written instructions to that effect and has ensured a valid legal basis under Applicable Data Protection Laws.

4. PERSONNEL:

Nisos shall take commercially reasonable steps to ascertain the reliability of any Nisos Personnel who Process Client Personal Data, and shall enter into written confidentiality agreements with all Nisos Personnel who Process Client Personal Data that are not subject to professional or statutory obligations of confidentiality.

5. RECORDS OF PROCESSING ACTIVITIES:

Nisos shall maintain records of its Processing activities carried out on behalf of Client as required by Article 30(2) of the GDPR and equivalent requirements under other Applicable Data Protection Laws. Nisos shall make such records available to Client and any Supervisory Authority upon request.

6. SECURITY

a. Nisos shall implement and maintain technical and organizational measures in relation to Client Personal Data designed to protect Client Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure of or access as described in Annex 3 (Security Measures) (the “Security Measures”).

b. Nisos may update the Security Measures from time to time, provided the updated measures do not materially decrease the overall protection of Client Personal Data.

c. Nisos shall Process Client Personal Data in the United States and the United Kingdom. Nisos shall not Process Client Personal Data in any other jurisdiction unless: (i) such Processing is necessary to provide the Services; (ii) Nisos complies with Applicable Data Protection Laws, including implementing any applicable Data Transfer Mechanism(s); (iii) any Sub-processor engaged in such jurisdiction is bound by written obligations offering a level of protection for Client Personal Data no less protective than the obligations set out in this DPA; and (iv) Nisos has disclosed such Processing locations in the Sub-processor List prior to commencing such Processing (which, in the case of Data Source Providers, may be disclosed by category in accordance with Paragraph 2(g) of Annex 1 (European Annex)).

7. DATA SUBJECT RIGHTS

a. Nisos, taking into account the nature of the Processing of Client Personal Data, shall provide Client with such assistance as may be reasonably necessary and technically feasible to assist Client in fulfilling its obligations to respond to Data Subject Requests. If Nisos receives a Data Subject Request, Client will be responsible for responding to any such request.

b. Nisos shall:

– promptly notify Client if it receives a Data Subject Request.

– not respond to any Data Subject Request, other than to advise the Data Subject to submit the request to Client, except on the written instructions of Client or as required by Applicable Data Protection Laws.

c. Operational clarifications:
i. When complying with its transparency obligations under Clause 8.3 of the EU SCCs, Client agrees that it shall not provide or otherwise make available, and shall take all appropriate steps to protect, Nisos’ and its licensors’ trade secrets, business secrets, confidential information and/or other commercially sensitive information.

ii. For the purposes of Clause 15.1(a) of the EU SCCs, except to the extent prohibited by applicable law and/or the relevant public authority, as between the Parties, Client agrees that it shall be solely responsible for making any notifications to relevant Data Subject(s) if and as required.

iii. Nisos shall provide reasonable cooperation and assistance to Client under this Section 7 at no additional charge. To the extent that Client’s requests for cooperation or assistance are excessive or unduly burdensome, Client shall reimburse Nisos for its reasonable costs incurred in providing such cooperation or assistance, at Nisos’ then-current professional services rates.

d. Nisos shall provide reasonable cooperation and assistance to Client in connection with any investigation, inquiry, or complaint by a Supervisory Authority or other regulatory body relating to the Processing of Client Personal Data under this DPA, including by providing information reasonably requested by Client and making relevant Nisos Personnel available for consultation, to the extent permitted by applicable law. Nisos shall provide such cooperation and assistance at no additional charge. To the extent that Client’s requests for cooperation or assistance are excessive or unduly burdensome, Client shall reimburse Nisos for its reasonable costs incurred in providing such cooperation or assistance, at Nisos’ then-current professional services rates.

8. PERSONAL DATA BREACH

Breach notification and assistance

a. Nisos shall notify Client without undue delay, and in any event within seventy-two (72) hours, upon Nisos’ discovering a Personal Data Breach affecting Client Personal Data. Nisos shall provide Client with information (insofar as such information is within Nisos’ possession and knowledge and does not otherwise compromise the security of any Personal Data Processed by Nisos) to allow Client to meet its obligations under the Applicable Data Protection Laws to report the Personal Data Breach. Nisos’ notification of or response to a Personal Data Breach shall not be construed as Nisos’ acknowledgment of any fault or liability with respect to the Personal Data Breach.

b. Nisos shall reasonably cooperate with Client and take such commercially reasonable steps as may be directed by Client to assist in the investigation of any such Personal Data Breach.

c. Client is solely responsible for complying with notification laws applicable to Client and fulfilling any third-party notification obligations related to any Personal Data Breaches.

Operational clarifications

d. Nisos shall provide reasonable cooperation and assistance to Client under this Section 8 at no additional charge. To the extent that Client’s requests for cooperation or assistance are excessive or unduly burdensome, Client shall reimburse Nisos for its reasonable costs incurred in providing such cooperation or assistance, at Nisos’ then-current professional services rates.

Notification to Nisos

e. If Client determines that a Personal Data Breach must be notified to any Supervisory Authority, any Data Subject(s), the public or others under Applicable Data Protection Laws, to the extent such notice directly or indirectly refers to or identifies Nisos, where permitted by applicable laws, Client agrees to:

– notify Nisos in advance.

– in good faith, consult with Nisos and consider any clarifications or corrections Nisos may reasonably recommend or request to any such notification, which: (i) relate to Nisos’ involvement in or relevance to such Personal Data Breach; and (ii) are consistent with applicable laws.

9. CLIENT’S RESPONSIBILITIES

a. Client agrees that, without limiting Nisos’ obligations under Section 6 (Security), Client is solely responsible for its use of the Services, including:
– making appropriate use of the Services to maintain a level of security appropriate to the risk in respect of the Client Personal Data.

– securing the account authentication credentials, systems and devices Client uses to access the Services.

– securing Client’s systems and devices that Nisos uses to provide the Services.

– backing up Client Personal Data.

b. Client agrees that the Services, the Security Measures, and Nisos’ commitments under this DPA are adequate to meet Client’s needs, including with respect to any security obligations of Client under Applicable Data Protection Laws, and provide a level of security appropriate to the risk in respect of the Client Personal Data.

c. Client acknowledges that the nature of the Services, which may include threat intelligence, investigations, digital risk monitoring, and personally identifiable information removal, may require Nisos to receive, access, or encounter certain categories of sensitive Client Personal Data in the course of performing the Services. Accordingly, the following restrictions apply:

i. Prohibited Data: Client shall not, under any circumstances, provide or otherwise make available to Nisos any Client Personal Data that contains:

– protected health information subject to the Health Insurance Portability and Accountability Act (HIPAA) or other information regarding an individual’s medical history, mental or physical condition, or medical treatment or diagnosis by a health care professional

– health insurance information

– biometric information

– any payment card information subject to the Payment Card Industry Data Security Standard

– Personal Data of children under 13 years of age

– any other information that falls within any special categories of personal data (as defined in GDPR) and/or data relating to criminal convictions and offenses or related security measures, except to the extent such data is encountered by Nisos in the course of performing the Services and is not submitted by Client (collectively, “Prohibited Data”).

ii. Operationally Sensitive Data:: Except where the Processing of such data is reasonably necessary for Nisos to perform the Services as described in the applicable Ordering Document (for example, where the Services involve the identification, monitoring, or removal of personally identifiable information, or the investigation of compromised credentials or leaked documents), Client shall not provide or otherwise make available to Nisos any Client Personal Data that contains:

– Social Security numbers or other government-issued identification numbers

– passwords to any online accounts

– credentials to any financial accounts

– tax return data

Where Client provides or authorizes Nisos to Process Operationally Sensitive Data, Client shall:
– identify the categories of Operationally Sensitive Data in the applicable Ordering Document or in written instructions to Nisos.

– ensure that a valid legal basis exists under Applicable Data Protection Laws for such Processing.

Nisos shall Process Operationally Sensitive Data solely as necessary to perform the Services and shall apply the Security Measures and any additional safeguards specified in the applicable Ordering Document.

Prohibited Data and Operationally Sensitive Data are collectively referred to as “Restricted Data.”

10. LIABILITY:

The total aggregate liability of either Party towards the other Party, howsoever arising, under or in connection with this DPA and the Data Transfer Mechanism(s) (if and as they apply) will under no circumstances exceed any limitations or caps on, and shall be subject to any exclusions of, liability and loss agreed by the Parties in the MSA; provided that, nothing in this Section 10 will affect any person’s liability to Data Subjects under the third-party beneficiary provisions of the Data Transfer Mechanism(s) (if and as they apply).

11. INCORPORATION AND PRECEDENCE

a. This DPA shall be incorporated into and form part of the MSA with effect from the Addendum Effective Date.

b. In the event of any conflict or inconsistency between:

– this DPA and the MSA, this DPA shall prevail, except that the scope of Client Personal Data shall be determined in accordance with Section 6.3 of the MSA; or

– any Data Transfer Mechanism(s) entered into pursuant to Paragraph 6 of Annex 1 (European Annex) and this DPA and/or the MSA, the Data Transfer Mechanism(s) shall prevail in respect of the Restricted Transfer to which they apply.

12. CUMULATIVE DATA SECURITY OBLIGATIONS:

The data security obligations set forth in the MSA (including any security practices, encryption requirements, and personnel screening obligations) shall apply cumulatively with the Security Measures set forth in this DPA. In the event of a conflict between the MSA’s data security provisions and this DPA, the more protective provision shall prevail.

Annex 1 – European Annex

1. PROCESSING OF CLIENT PERSONAL DATA

a. The Parties acknowledge and agree that the details of Nisos’ Processing of Personal Data under this DPA and the MSA (including the respective roles of the Parties relating to such Processing) are as set out in Attachment 1 of Annex 1 (European Annex) to the DPA.

b. Where Nisos receives an instruction from Client that, in its reasonable opinion, infringes the GDPR, Nisos shall inform Client.

c. Client acknowledges and agrees that any instructions issued by Client with regards to the Processing of Client Personal Data by or on behalf of Nisos pursuant to or in connection with the MSA shall be in strict compliance with the GDPR and all other applicable laws.

2. SUB-PROCESSING

a. Client generally authorizes Nisos to appoint Sub-processors in accordance with this Paragraph 2.

b. Nisos may continue to use those Sub-processors already engaged by Nisos as at the date of this DPA (as those Sub-processors are shown, together with their respective functions and locations, in the Sub-processor List).

c. Nisos shall give Client prior written notice of the appointment of any proposed Sub-processor, including reasonable details of the Processing to be undertaken by the Sub-processor, by updating the Sub-processor List and notifying Client via email to Client’s contact point as set out in Attachment 1 of Annex 1 (European Annex). If, within thirty (30) days of receipt of that notice, Client notifies Nisos in writing of any objections (on reasonable grounds) to the proposed appointment:

i. Nisos shall use reasonable efforts to make available a commercially reasonable change in the provision of the Services, which avoids the use of that proposed Sub-processor.

ii. Where: (i) such a change cannot be made within thirty (30) days from Nisos’ receipt of Client’s notice; (ii) no commercially reasonable change is available; and/or (iii) Client declines to bear the cost of the proposed change, then either Party may by written notice to the other Party with immediate effect terminate the MSA, either in whole or to the extent that it relates to the Services which require the use of the proposed Sub-processor, as its sole and exclusive remedy.

d. If Client does not object to Nisos’ appointment of a Sub-processor during the objection period referred to in Paragraph 2(c), Client shall be deemed to have approved the engagement and ongoing use of that Sub-processor.

e. With respect to each Sub-processor, Nisos shall maintain a written contract between Nisos and the Sub-processor that includes terms which offer at least an equivalent level of protection for Client Personal Data as those set out in this DPA (including the Security Measures). Nisos shall remain liable for any breach of this DPA caused by a Sub-processor.

f. Operational clarifications:

i. The terms and conditions of this Paragraph 2 apply in relation to Nisos’ appointment and use of Sub-processors under the Data Transfer Mechanism(s).

ii. Any approval by Client of Nisos’ appointment of a Sub-processor that is given expressly or deemed given pursuant to this Paragraph 2 constitutes Client’s documented instructions to effect disclosures and onward transfers to any relevant Sub-processors if and as required under Clause 8.8 of the EU SCCs.

3. DATA PROTECTION IMPACT ASSESSMENT AND PRIOR CONSULTATION

a. Nisos, taking into account the nature of the Processing and the information available to Nisos, shall provide reasonable assistance to Client with any data protection impact assessments and prior consultations with Supervisory Authorities which Client reasonably considers to be required of it by Article 35 or Article 36 of the GDPR, in each case solely in relation to Processing of Client Personal Data by Nisos.

b. Nisos shall provide reasonable cooperation and assistance to Client under Paragraph 3(a) at no additional charge. To the extent that Client’s requests for cooperation or assistance are excessive or unduly burdensome, Client shall reimburse Nisos for its reasonable costs incurred in providing such cooperation or assistance, at Nisos’ then-current professional services rates.

c. Client may issue supplementary written instructions regarding the Processing of Client Personal Data, provided that such instructions are consistent with the terms of this DPA and the MSA. Nisos shall comply with such supplementary instructions to the extent they are reasonable and technically feasible. If Nisos determines that a supplementary instruction infringes Applicable Data Protection Laws, Nisos shall promptly inform Client.

4. RETURN AND DELETION

a. Subject to Paragraph 4(b) and 4(c), upon the date of cessation of any Services involving the Processing of Client Personal Data (the “Cessation Date”), Nisos shall promptly cease all Processing of Client Personal Data for any purpose other than for storage or as otherwise permitted or required under this DPA.

b. Subject to Paragraph 4(d), to the extent technically possible in the circumstances (as determined in Nisos’ sole discretion), on written request to Nisos (to be made no later than thirty (30) days after the Cessation Date (“Post-cessation Storage Period”)), Nisos shall within thirty (30) days of such request:

i. return a complete copy of all Client Personal Data within Nisos’ possession to Client by secure file transfer, promptly following which Nisos shall delete or irreversibly anonymize all other copies of such Client Personal Data.

ii. either (at its option) delete or irreversibly anonymize all Client Personal Data within Nisos’ possession.

c. Subject to Paragraph 4(d), in the event that during the Post-cessation Storage Period, Client does not instruct Nisos in writing to either delete or return Client Personal Data pursuant to Paragraph 4(b), Nisos shall promptly after the expiry of the Post-cessation Storage Period either (at its option) delete or irreversibly render anonymous, all Client Personal Data then within Nisos’ possession to the fullest extent technically possible in the circumstances.

d. Nisos may retain Client Personal Data (i) where permitted or required by applicable law, for such period as may be required by such applicable law, or (ii) to the extent contained in Deliverables retained by Nisos in accordance with Section 2.8 of the MSA, provided that Nisos shall:

i. maintain the confidentiality of all such Client Personal Data.

ii. Process the Client Personal Data only as necessary for the purpose(s) specified in the applicable law permitting or requiring such retention or in Section 2.8 of the MSA, as applicable..

e. Certification of deletion of Client Personal Data as described in Clauses 8.5 and 16(d) of the EU SCCs shall be provided only upon Client’s written request.

5. AUDIT RIGHTS

a. Nisos shall make available to Client on request, such information as Nisos (acting reasonably) considers appropriate in the circumstances to demonstrate its compliance with this DPA.

b. Subject to Paragraphs 5(c) through 5(h), in the event that Client (acting reasonably) is able to provide documentary evidence that the information made available by Nisos pursuant to Paragraph 5(a) is not sufficient in the circumstances to demonstrate Nisos’ compliance with this DPA, Nisos shall allow for and contribute to audits, including on-premise inspections, by Client or an auditor mandated by Client in relation to the Processing of Client Personal Data by Nisos.

c. Client shall give Nisos reasonable notice of any audit or inspection to be conducted under Paragraph 5(b) (which shall in no event be less than thirty (30) days’ notice) and shall use its best efforts (and ensure that each of its mandated auditors uses its best efforts) to avoid causing any destruction, damage, injury or disruption to Nisos’ premises, equipment, Personnel, data, and business (including any interference with the confidentiality or security of the data of Nisos’ other clients or the availability of Nisos’ services to such other clients).

d. Prior to conducting any audit, Client must submit a detailed proposed audit plan providing for the confidential treatment of all information exchanged in connection with the audit and any reports regarding the results or findings thereof. The proposed audit plan must describe the proposed scope, duration, and start date of the audit. Nisos will review the proposed audit plan and provide Client with any concerns or questions (for example, any request for information that could compromise Nisos security, privacy, employment or other relevant policies). Nisos will work cooperatively with Client to agree on a final audit plan.

e. If the controls or measures to be assessed in the requested audit are addressed in a SOC 2 Type II, ISO, NIST or similar audit report performed by a qualified third-party auditor within twelve (12) months of Client’s audit request (“Audit Report”) and Nisos has confirmed in writing that there are no known material changes in the controls audited and covered by such Audit Report(s), Client agrees to accept provision of such Audit Report(s) in lieu of requesting an audit of such controls or measures.

f. Nisos need not give access to its premises for the purposes of such an audit or inspection:

i. where an Audit Report is accepted in lieu of such controls or measures in accordance with Paragraph 5(e).

ii. to any individual unless they produce reasonable evidence of their identity.

iii. to any auditor whom Nisos has not approved in advance (acting reasonably).

iv. to any individual who has not entered into a non-disclosure agreement with Nisos on terms acceptable to Nisos.

v. outside normal business hours at those premises.

vi. on more than one occasion in any calendar year during the term of the MSA, except for any audits or inspections which Client is required to carry out under the GDPR or by a Supervisory Authority.

g. Data Source Providers
i. Notwithstanding Paragraphs 2(b) and 2(c), Nisos may identify Data Source Providers in the Sub-processor List by category, together with the function of, and the country or countries of Processing for each category, rather than by name. Client acknowledges that the identity and combination of the Data Source Providers used by Nisos constitute Nisos’ Confidential Information and trade secrets.

ii. Nisos shall provide notice in accordance with Paragraph 2(c) only where Nisos (a) adds a new category of Data Source Provider to the Sub-processor List, or (b) engages a Data Source Provider that will Process Client Personal Data in a country not then identified in the Sub-processor List for the relevant category. The engagement or replacement of a Data Source Provider within a category and country already identified in the Sub-processor List shall not require notice under Paragraph 2(c), and Client’s approval (express or deemed) of a category constitutes approval of each Data Source Provider within that category.

iii. Upon Client’s written request, Nisos shall make available to Client personnel responsible for data protection compliance the identity of each Data Source Provider that Processes Client Personal Data on Client’s behalf, subject to confidentiality obligations no less protective than those set out in the MSA. Client shall use such information solely to assess and verify compliance with this DPA and Applicable Data Protection Laws and shall not disclose it to any third party except a Supervisory Authority or as required by applicable law.

iv. Without limiting Paragraph 2(e), Nisos shall ensure that each Data Source Provider is bound by written obligations that (a) limit its Processing of Client Personal Data to what is necessary to execute queries submitted by or on behalf of Nisos and return results to Nisos; (b) prohibit it from retaining Client Personal Data beyond what is necessary for that purpose, except for query logs retained solely for billing, security and abuse-prevention purposes for a limited period; and (c) prohibit it from using Client Personal Data for its own purposes, including to build, enrich, train or improve any dataset or model, or disclosing Client Personal Data to any third party.

h. Operational clarifications:
i. Nisos shall provide reasonable cooperation and assistance to Client under this Paragraph 5 at no additional charge (excluding any costs incurred in the procurement, preparation or delivery of Audit Reports to Client pursuant to Paragraph 5(e)). To the extent that Client’s requests for cooperation or assistance are excessive or unduly burdensome, Client shall reimburse Nisos for its reasonable costs incurred in providing such cooperation or assistance at Nisos’ then-current professional services rates.

ii. The audits described in Clauses 8.9(c) and 8.9(d) of the EU SCCs shall be subject to any relevant terms and conditions detailed in this Paragraph 5.

6. RESTRICTED TRANSFERS

a. The Parties acknowledge that Client’s transmission of Client Personal Data to Nisos hereunder may involve a Restricted Transfer. The relevant Data Transfer Mechanism(s) that may be entered into under Paragraph 6(b) and/or 6(c) shall apply and have effect only if and to the extent permitted and required under the EU GDPR and/or UK GDPR (if and as applicable) to establish a valid basis under Chapter V of the EU GDPR and/or UK GDPR in respect of the transfer from Client to Nisos of Client Personal Data.

EU Restricted Transfers

b. To the extent that any Processing of Client Personal Data under this DPA involves an EU Restricted Transfer from Client to Nisos, the Parties shall comply with their respective obligations set out in the EU SCCs. The following Modules of the EU SCCs apply in the manner set out below:

i. Module One of the EU SCCs applies to any EU Restricted Transfer involving Service Data; and/or

ii. Module Two of the EU SCCs applies to any EU Restricted Transfer involving Client Personal Data.

UK Restricted Transfers

c. To the extent that any Processing of Client Personal Data under this DPA involves a UK Restricted Transfer from Client to Nisos:

i. the relevant EU SCCs entered into in accordance with Paragraph 6(b) of this Annex 1 (European Annex) shall apply to that UK Restricted Transfer as varied by the UK Addendum.

ii. the Parties agree that the manner of the presentation of the information included in the UK Addendum shall not operate or be construed so as to reduce the Appropriate Safeguards (as defined in Section 3 of Part 2 of the UK Addendum).

Swiss Restricted Transfers

d. To the extent that any Processing of Client Personal Data under this DPA involves a Swiss Restricted Transfer from Client to Nisos, the EU SCCs entered into in accordance with Paragraph 6(b) of this Annex 1 (European Annex) shall apply to such transfer as modified by the Swiss Schedule set out in Attachment 4 of Annex 1 (European Annex).

Data Privacy Framework (DPF)

e. To the extent Nisos maintains self-certification under the EU-U.S. Data Privacy Framework, the UK Extension to the EU-U.S. Data Privacy Framework, and/or the Swiss-U.S. Data Privacy Framework (collectively, the “Data Privacy Framework” or “DPF”), such certification may serve as a valid transfer mechanism for applicable Restricted Transfers in lieu of, or in addition to, the EU SCCs, the UK Addendum and/or the EU SCCs as modified by the Swiss Schedule, to the extent recognized under Applicable Data Protection Laws. Nisos shall maintain its DPF certification for the duration of the MSA and shall notify Client promptly if its certification lapses, is revoked, or is otherwise invalidated, in which case the EU SCCs, the UK Addendum and/or the EU SCCs as modified by the Swiss Schedule (as applicable) shall continue to apply as the applicable Data Transfer Mechanism.

Adoption of new transfer mechanism

f. Nisos may on notice vary this DPA and replace the relevant Data Transfer Mechanism(s) with:

i. any new form, version, or module of the relevant Data Transfer Mechanism(s) or any replacement therefor prepared and populated accordingly.

ii. another transfer mechanism, other than the current Data Transfer Mechanism(s).

that enables the lawful transfer of Client Personal Data to Nisos under this DPA in compliance with Chapter V of the GDPR.

Attachment 1 of Annex 1 (European Annex)

Note: This Attachment 1 of Annex 1 (European Annex) to the DPA includes certain details of the Processing of Personal Data as required by Article 28(3) GDPR and to populate the Appendices to the EU SCCs and UK Addendum.

PART 1: DETAILS OF THE PARTIES

NISOS / ‘DATA IMPORTER’ DETAILS

 

Name: Nisos (as set out in the preamble to the DPA)
Address: As set out in the preamble to the DPA
Contact Details for Data Protection:

Role: Chief Financial Officer

Email: privacy@nisos.com

Nisos Activities: Nisos is a human risk intelligence company that uses its proprietary technology to help clients proactively identify threats to their businesses.
Role:

In respect of Client Personal Data: Processor

In respect of Service Data: Controller

CLIENT / ‘DATA EXPORTER’ DETAILS

 

Name:

Client (as set out in the preamble to the DPA)

Address:

Client’s address is Client’s principal business trading address – unless otherwise notified to the email address set out under ‘Nisos / ‘Data Importer’ Details’

Contact Details for Data Protection:

Unless a Data Protection contact is provided on the Ordering Document, the primary contact identified in the applicable Ordering Document, or if no primary contact is specified, the signatory of the applicable Ordering Document. 

Client Activities:

Client’s activities relevant to this DPA are the use and receipt of the Services under and in accordance with, and for the purposes anticipated and permitted in, the MSA as part of its ongoing business operations.

Role:

Controller

PART 2: DETAILS OF NISOS’ PROCESSING AS A PROCESSOR

 

Categories of Data Subjects:

Any individuals whose Personal Data is comprised within data submitted to the Services by or on behalf of Client under the MSA  – but may include:

  • Client’s and its affiliates’:
    • staff;
    • customers, clients, (sub-)licensees, users and end-users, website visitors and marketing prospects;
    • suppliers, service providers, consultants, advisers and other providers of goods or services;
    • distributors, resellers, sales agents, introducers, sales representatives, collaborators, joint venturers and other commercial partners;
    • shareholders, partners, members and supporters; and
    • advisers, consultants and other professionals and experts.
  • Data Subjects identified in data submitted by or on behalf of Client in connection with Nisos’ threat detection.

Where any of the above is a business or organization, it includes their staff.

Each category includes current, past and prospective Data Subjects.

Categories of Personal Data:

Any Personal Data comprised within data submitted to the Services by or on behalf of Client under the MSA, and/or obtained by Nisos in its performance of the Services – but may include:

  • Personal details, including any information that identifies the Data Subject and their personal characteristics, including: name, address, contact details (including email address, telephone details and other contact information), age, date of birth, sex, and physical description.
  • User endpoint behavior (including user account activity and metadata, applications executed on endpoints, and accessed URLs).
  • Technological details, such as internet protocol (IP) addresses, unique identifiers and numbers (including unique identifier in tracking cookies or similar technology), pseudonymous identifiers, precise and imprecise location data, internet / application / program activity data, and device IDs and addresses.
  • Any Personal Data relevant to a threat, both actual and suspected, that is submitted by or on behalf of Client.

Sensitive Categories of Data, and associated additional restrictions/safeguards:

Categories of sensitive data:

Prohibited Data (as defined in Section 9(c)) must not be submitted to the Services. Operationally Sensitive Data may be submitted only in accordance with Section 9(c).

Additional safeguards for sensitive data:

Operationally Sensitive Data (as defined in Section 9(c) of the DPA) is processed solely as necessary to perform the Services, subject to the Security Measures set forth in Annex 3 and any additional safeguards specified in the applicable Ordering Document. Prohibited Data (as defined in Section 9(c) of the DPA) must not be submitted to the Services by Client.

Frequency of transfer:

Ongoing

Nature of the Processing:

Processing operations required in order to provide the Services in accordance with the MSA.

Purpose of the Processing:

Client Personal Data will be processed: (i) as necessary to provide the Services as initiated by Client in its use thereof, and (ii) to comply with any other reasonable instructions provided by Client in accordance with the terms of this DPA.

Duration of Processing / Retention Period:

For the period determined in accordance with the MSA and DPA, including Paragraph 4 of Annex 1 (European Annex) to the DPA.

Transfers to (sub-)processors:

Transfers to Sub-processors are as, and for the purposes, described from time to time in the Sub-processor List (as may be updated from time to time in accordance with Paragraph 2 of Annex 1 (European Annex) to the DPA).

PART 3: DETAILS OF NISOS’ PROCESSING AS A CONTROLLER

 

Categories of Data Subjects: Any individuals whose Personal Data is comprised within data submitted to the Services by or on behalf of Client under the MSA, and/or obtained by Nisos in its performance of the Services – but may include Data Subjects identified by Nisos as part of Nisos’ threat detection.
Categories of Personal Data:

Any Personal Data comprised within data submitted to the Services by or on behalf of Client under the MSA, and/or obtained by Nisos in its performance of the Services – but may include:

  • Personal details, including any information that identifies the Data Subject and their personal characteristics, including: name, address, contact details (including email address, telephone details and other contact information), age, date of birth, sex, and physical description.
  • User endpoint behavior (including user account activity and metadata, applications executed on endpoints, and accessed URLs).
  • Technological details, such as internet protocol (IP) addresses, unique identifiers and numbers (including unique identifier in tracking cookies or similar technology), pseudonymous identifiers, precise and imprecise location data, internet / application / program activity data, and device IDs and addresses.
  • Any Personal Data relevant to a threat, both actual and suspected.
Sensitive Categories of Data, and associated additional restrictions/safeguards:

Categories of sensitive data:

Prohibited Data (as defined in Section 9(c)) must not be submitted to the Services. Operationally Sensitive Data may be submitted only in accordance with Section 9(c).

Additional safeguards for sensitive data:

Operationally Sensitive Data (as defined in Section 9(c) of the DPA) is processed solely as necessary to perform the Services, subject to the Security Measures set forth in Annex 3 and any additional safeguards specified in the applicable Ordering Document. Prohibited Data (as defined in Section 9(c) of the DPA) must not be submitted to the Services by Client.

Frequency of transfer: Ongoing
Nature of the Processing: Processing operations required in order to provide, improve, develop, optimize and maintain the Services.
Purpose of the Processing: Service Data is Processed to provide, improve, develop, optimize and maintain the Services.
Duration of Processing / Retention Period: For as long as necessary to achieve the purposes of the Processing.
Transfers to (sub-)processors: Nisos shall comply with Applicable Data Protection Laws when appointing Processors to Process Service Data.

Attachment 2 of Annex 1 (European Annex)

EU SCCs

The standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council, as approved by Commission Implementing Decision (EU) 2021/914 of 4 June 2021 (as may be amended, superseded, or replaced) (the “EU SCCs”), are hereby incorporated by reference into this DPA as if set out in full herein.
For the purposes of the EU SCCs:

Module One (Controller to Controller) applies to any EU Restricted Transfer involving Service Data, and Module Two (Controller to Processor) applies to any EU Restricted Transfer involving Client Personal Data;

in Clause 7, the optional docking clause is not used;

in Clause 9(a), Option 2 (general written authorization) applies, and the time period for prior notice of Sub-processor changes is as set out in Paragraph 2 of Annex 1 (European Annex) to this DPA;

in Clause 13, the competent supervisory authority is the Data Protection Commissioner of Ireland;

in Clause 17, Option 1 applies and the EU SCCs are governed by the law of Ireland;

in Clause 18(b), disputes are resolved before the courts of Ireland; and
the Appendix Information is completed as follows:

Annex I.A (List of Parties): Part 1 of Attachment 1 of Annex 1 (European Annex) to this DPA;

Annex I.B (Description of Transfer): Part 2 and Part 3 of Attachment 1 of Annex 1 (European Annex) to this DPA;

Annex I.C (Competent Supervisory Authority): the Data Protection Commissioner of Ireland; and

Annex II (Technical and Organizational Measures): as set out in Annex 3 (Security Measures) of this DPA.

Attachment 3 of Annex 1 (European Annex)

UK Addendum

The International Data Transfer Addendum to the EU Commission Standard Contractual Clauses (Version B1.0), as issued by the ICO and in force from 21 March 2022 (as may be amended, superseded, or replaced) (the “UK Addendum”), is hereby incorporated by reference into this DPA as if set out in full herein.
For the purposes of the UK Addendum:

Table 1 (Parties) is completed as follows: the start date is the Addendum Effective Date; the Exporter is Client and the Importer is Nisos, with the Parties’ details and key contacts as set out in Part 1 of Attachment 1 of Annex 1 (European Annex) to this DPA;

Table 2 (Selected SCCs, Modules and Selected Clauses): the Addendum EU SCCs are the EU SCCs incorporated by reference in Attachment 2 of Annex 1 (European Annex) to this DPA, including the elections specified therein;

Table 3 (Appendix Information) is completed as follows: Annex 1A (List of Parties) as set out in Part 1 of Attachment 1 of Annex 1 (European Annex); Annex 1B (Description of Transfer) as set out in Part 2 and Part 3 of Attachment 1 of Annex 1 (European Annex); Annex II (Technical and Organizational Measures) as set out in Annex 3 (Security Measures) of this DPA; and Annex III (List of Sub-processors) as set out in the Sub-processor List;

Table 4 (Ending this Addendum when the Approved Addendum Changes): the Importer may end this Addendum in accordance with Section 19 of the Approved Addendum;

the UK Addendum is governed by the laws of England and Wales and any dispute arising from it is resolved by the courts of England and Wales; and

the competent supervisory authority for the purposes of the UK Addendum is the UK Information Commissioner’s Office.

Attachment 4 of Annex 1 (European Annex)

Swiss Schedule

Modified EU SCCs. The Parties agree that any Swiss Restricted Transfer is made pursuant to the EU SCCs incorporated by reference in Attachment 2 of Annex 1 (European Annex) to this DPA, with the following modifications:

the terms “General Data Protection Regulation”, “Regulation (EU) 2016/679” and “GDPR” as used in the EU SCCs are interpreted to include the FADP with respect to any Swiss Restricted Transfer;

references to “EU”, “Union” and “Member State” in the EU SCCs are interpreted, with respect to any Swiss Restricted Transfer, as references to Switzerland;

Clause 13 of the EU SCCs is modified to provide that the FDPIC has authority over any Swiss Restricted Transfer governed by the FADP, and the competent supervisory authority identified in Attachment 2 of Annex 1 (European Annex) has authority over any Restricted Transfer governed by the EU GDPR; in all other respects, the requirements of Clause 13 of the EU SCCs continue to apply; and

the term “EU Member State” as used in the EU SCCs is not interpreted so as to exclude Data Subjects in Switzerland from exercising their rights in their place of habitual residence in accordance with Clause 18(c) of the EU SCCs.

Competent supervisory authority. Where Client is established in Switzerland or otherwise falls within the territorial scope of the FADP, the FDPIC shall act as the competent supervisory authority insofar as the relevant Restricted Transfer is governed by the FADP.

Annex 2 – US Privacy Annex

1. The business purposes and services for which Nisos is Processing personal information are for Nisos to provide the Services to and on behalf of Client as set forth in the MSA. It is the Parties’ intent that with respect to any personal information, Nisos is a service provider (and, to the extent applicable under the CPRA, a service provider as defined therein). Nisos:
a. acknowledges that personal information is disclosed by Client only for the limited and specific purposes described in the MSA;

b. shall comply with applicable obligations under the CCPA and US State Privacy Laws and shall provide the same level of privacy protection to personal information as is required by the CCPA and US State Privacy Laws;

c. agrees that Client has the right to take reasonable and appropriate steps, subject to Section 5 (Audit Rights) of Annex 1 (European Annex), to help ensure that Nisos’ use of personal information is consistent with Client’s obligations under the CCPA and US State Privacy Laws;

d. shall notify Client in writing if Nisos determines that it can no longer meet its obligations under the CCPA or US State Privacy Laws; and

e. agrees that Client has the right, upon notice (including pursuant to Section 1(d) above), to take reasonable and appropriate steps to stop and remediate unauthorized use of personal information.

2. Nisos shall not:
a. sell or share any personal information;

b. retain, use or disclose any personal information for any purpose other than for the business purposes specified in the MSA, including retaining, using, or disclosing the personal information for a commercial purpose other than the business purposes specified in the MSA, or as otherwise permitted by the CCPA or US State Privacy Laws;

c. retain, use or disclose the personal information outside of the direct business relationship between Nisos and Client; or

d. combine personal information received pursuant to the MSA with personal information (i) received from or on behalf of another person, or (ii) collected from Nisos’ own interaction with any consumer to whom such personal information pertains, except as and to the extent necessary as part of Nisos’ provision of the Services.

3. Nisos hereby certifies that it understands and will comply with the obligations set out in this Annex 2.

4. Nisos shall implement reasonable security procedures and practices appropriate to the nature of the personal information received from, or on behalf of, Client, in accordance with Annex 3 (Security Measures) of this DPA.

5. When Nisos engages any Sub-processor to Process personal information, Nisos shall notify Client of such Sub-processor engagements in accordance with Paragraph 2 of Annex 1 (European Annex), and that notice shall satisfy Nisos’ obligation under the CCPA and US State Privacy Laws to give notice of, and an opportunity to object to, such engagements.

6. Client may conduct audits, in accordance with Section 5 (Audit Rights) of Annex 1 (European Annex), to help ensure that Nisos’ use of personal information is consistent with Nisos’ obligations under the CCPA and US State Privacy Laws.

7. The Parties acknowledge that Nisos’ retention, use and disclosure of personal information authorized by Client’s instructions documented in the MSA and this DPA are integral to Nisos’ provision of the Services and the business relationship between the Parties. The exchange of Client Personal Data does not form part of the consideration exchanged between the Parties in respect of the MSA or any other business dealings.

Annex 3 – Security Measures

As from the Addendum Effective Date, Nisos will implement and maintain the Security Measures as set out in this Annex 3. Nisos maintains a SOC 2 Type II certification. On Client’s written request (no more than once per calendar year), Nisos shall make available a summary or copy of its most recent SOC 2 Type II audit report, subject to reasonable confidentiality obligations.

1. Organizational management and dedicated staff responsible for the development, implementation and maintenance of Nisos’ information security program.

2. Audit and risk assessment procedures for the purposes of periodic review and assessment of risks to Nisos’ organization, monitoring and maintaining compliance with Nisos’ policies and procedures, and reporting the condition of its information security and compliance to internal senior management.

3. Data security controls which include at a minimum logical segregation of data, restricted (e.g. role-based) access and monitoring, and utilization of commercially available and industry standard encryption technologies for Client Personal Data.

4. Logical access controls designed to manage electronic access to data and system functionality based on authority levels and job functions.

5. Password controls designed to manage and control password strength, expiration and usage.

6. System audit or event logging and related monitoring procedures to proactively record user access and system activity.

7. Physical and environmental security of data centers, server room facilities and other areas containing Client Personal Data designed to protect information assets from unauthorized physical access or damage.

8. Operational procedures and controls to provide for configuration, monitoring and maintenance of technology and information systems, including secure disposal of systems and media to render all information or data contained therein as undecipherable or unrecoverable prior to final disposal or release from Nisos’ possession.

9. Change management procedures and tracking mechanisms designed to test, approve and monitor all material changes to Nisos’ technology and information assets.

10. Incident management procedures designed to allow Nisos to investigate, respond to, mitigate and notify of events related to Nisos’ technology and information assets.
Network security controls that provide for the use of enterprise firewalls and intrusion detection systems designed to protect systems from intrusion and limit the scope of any successful attack.
Vulnerability assessment and threat protection technologies and scheduled monitoring procedures designed to identify, assess, mitigate and protect against identified security threats, viruses and other malicious code.
Business resiliency/continuity and disaster recovery procedures designed to maintain service and/or recovery from foreseeable emergency situations or disasters.