Updated: August 10, 2025
This Data Processing Addendum ("DPA") forms part of the Master Services Agreement ("Agreement") between: (i) Vendor (identified in the signature line below) and its affiliates ("Vendor"); and (ii) Caliza, LLC d/b/a Landing and its affiliates ("Company") only where required by the General Data Protection Regulation ("GDPR") or other applicable privacy legislation.
This DPA supersedes any previous agreement between the parties regarding the subject matter herein, i.e., data privacy and security as applicable to the Data Protection Laws (defined below).
In consideration of the mutual obligations set out herein, the parties hereby agree that the terms and conditions set out below shall be added as an addendum to the Agreement.
"Company Personal Data" means personal data Processed by Vendor on behalf of Company in provision of the products and/or services.
"CCPA" means the California Consumer Privacy Act, as amended by the California Privacy Rights Act or further California legislation/regulation.
"Data Privacy Framework" or "DPF" means the EU-U.S. legal framework for cross-border transfers of Personal Data between the European Union and the United States and includes the UK Extension to the EU-U.S. DPF and the Swiss-U.S. DPF.
"Data Protection Laws" means all applicable laws and regulations relating to the Processing of Personal Data and privacy that may exist in the relevant jurisdiction, including, where applicable:
Where the GDPR is specifically mentioned, the same requirements will apply to any other applicable Data Protection Law's equivalent requirement.
"Data Subject" means the individual to whom Company Personal Data relates.
"Personal Data" means any information that relates to a Data Subject, including but not limited to a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of the Data Subject.
"Process" or "Processing" means any operation or set of operations which is performed on Company Personal Data, whether or not by automated means, such as the collection, recording, organization, structuring, storage, alteration, retrieval, consultation, use, disclosure, disposal, restriction, access, dissemination, combination, adaption, copying, transfer, erasure and/or destruction of Company Personal Data.
"Security Breach" means any unauthorized access to or interference with Vendor's facilities, networks or systems where Company Personal Data resides or any misuse or unlawful or accidental loss, destruction, alteration or unauthorized Processing of Company Personal Data.
"Standard Contractual Clauses" or "SCCs" means:
"Third Party" means a party other than Vendor or Company.
The terms "controller", "processor", and "supervisory authority" as used in this DPA will have the meanings ascribed to them in the applicable Data Protection Laws.
All other non-defined but capitalized terms shall have the meaning set forth in the Agreement or the applicable Data Protection Laws.
Vendor shall:
(a) comply with all applicable Data Protection Laws in the Processing of Company Personal Data;
(b) not Process Company Personal Data other than as instructed by Company unless Processing is required by applicable laws to which the relevant Vendor is subject, in which case Vendor shall to the extent permitted by applicable laws inform Company of that legal requirement before Processing of that Personal Data;
(c) promptly notify Company of any third party request to: (i) restrict the Processing of Company Personal Data; (ii) port Company Personal Data to a third party; or (iii) access, rectify or erase Company Personal Data. Vendor will not respond to such request except on Company's instructions and will further assist Company, at Company's request, in complying with Company's obligations to respond to requests and complaints directed to Company with respect to Company Personal Data Processed by Vendor;
(d) ensure that all personnel who Process Company Personal Data are bound by obligations of confidentiality at least as protective as those imposed on Vendor under this DPA;
(e) provide reasonable assistance to Company with any data protection impact assessments, transfer impact assessments, and prior consultations with supervisory authorities or other competent data privacy authorities which Company reasonably considers to be required by Article 35 or 36 of the GDPR or equivalent provisions of any other Data Protection Law; and
(f) keep detailed, accurate, and up-to-date records regarding any processing of Company Personal Data it carries out for Company, including but not limited to, the access, control, and security of the Company Personal Data, approved subcontractors and affiliates, the processing purposes, and any other records required by the applicable Data Protection Laws.
(g) (i) provide clear, accurate, and timely disclosures regarding any artificial intelligence ("AI") technologies or automated decision-making processes employed in the provision of services, (ii) acknowledges and agrees that any processing of Company Personal Data through AI systems or algorithms shall be strictly limited to the scope, purposes, and processing instructions explicitly provided by Company and will be in compliance with all applicable laws, and (iii) will not allow Company Personal Data to be used to train AI models.
The subject matter and duration of Processing, nature and purpose of Processing, specific types of Company Personal Data that Vendor will Process, and categories of Data Subjects whose Company Personal Data will be Processed are set forth in Schedule 1 (Details of Processing of Company Personal Data). For purposes of this DPA, the parties agree that Company is a controller of Company Personal Data and Vendor is a processor of such data.
For purposes of U.S. Data Protection Laws (including the CCPA), "controller" includes "business"; "processor" includes "service provider"; "Data Subject" includes "consumer"; and "Personal Data" includes "personal information." Vendor is a service provider and Company is a business.
Company instructs Vendor to Process Company Personal Data: (a) in accordance with the Agreement and any applicable Supplement; (b) as otherwise necessary to provide the products and/or services to the Company; (c) as necessary to comply with applicable law or regulation; and (d) to comply with other reasonable written instructions provided by Company where such instructions are consistent with the terms of the Agreement. Company will ensure that its instructions for the Processing of Company Personal Data shall comply with the Data Protection Laws. As between the parties, Company shall have sole responsibility for the accuracy, quality, and legality of Company Personal Data and the means by which Company obtained the Company Personal Data.
Vendor shall only Process Company Personal Data in accordance with Company's instructions and shall treat Company Personal Data as confidential information. If Vendor believes or becomes aware that any of Company's instructions conflict with any Data Protection Laws, Vendor shall inform Company within a reasonable timeframe. Vendor may Process Company Personal Data other than on the written instructions of Company if it is required under applicable law to which Vendor is subject. In this situation, Vendor shall inform Company of such requirement before Vendor Processes the Company Personal Data unless prohibited by applicable law.
To the extent Vendor's Processing of Personal Data is subject to the CCPA, Vendor certifies that it shall not: (a) retain, use, or disclose Company Personal Data other than as provided for in the Agreement, as needed to provide the products and/or services, to detect security incidents, to protect against fraudulent or illegal activity, to retain sub-processors in accordance with this DPA, or as otherwise permitted by the CCPA; or (b) sell or share Company Personal Data.
Company acknowledges that Vendor may engage third-party sub-processors in connection with the provision of services and hereby provides general written authorization for Vendor's current sub-processors. Vendor will be responsible for the acts and omissions of its sub-processors. Vendor will impose contractual obligations on its sub-processors that are at least equivalent to those obligations imposed on Vendor under this DPA. Vendor shall make a list of sub-processors available to Company upon request, update Company when a new sub-processor is engaged, and honor objections to specific sub-processors where made. Company may object to any sub-processor by communicating such objection to Vendor within thirty (30) days of an update, and the parties will work in good faith to resolve the objection.
Vendor shall not subcontract or engage third-party providers to perform AI-based processing activities involving Company Personal Data without prior written authorization from Company. Any authorized sub-processors must adhere strictly to the requirements of this Addendum.
Where Vendor subcontracts its obligations, it shall do so only by way of a written agreement with the sub-processor which imposes contractual obligations that are at least equivalent to those obligations imposed on Vendor under this DPA. The parties agree that copies of the agreements with authorized sub-processors that must be provided pursuant to applicable Standard Contractual Clauses will be provided only upon written request by Company.
Where the sub-processor fails to fulfill its data protection obligations under such written agreement, Vendor shall remain fully liable to Company for the performance of the sub-processor's obligations under such agreement.
Vendor will implement, maintain and monitor a comprehensive written information security policy that contains appropriate administrative, technical and organizational safeguards to ensure the security and confidentiality of Company Personal Data and to prevent unauthorized or unlawful Processing of Company Personal Data and any loss, destruction of or damage to Company Personal Data ("Information Security Program"). The safeguards will be appropriate to the nature of the Company Personal Data Vendor Processes and will meet or exceed prevailing industry standards. Vendor will maintain the ability to restore the availability and access to Company Personal Data in a timely manner in the event of a physical or technical incident.
Vendor will regularly test, assess, and evaluate the effectiveness of the Information Security Program for ensuring the secure Processing of Company Personal Data. Vendor will provide Company upon request with the results of all tests and any other audit, review or examination relating to its Information Security Program and take appropriate steps to protect against identified risks. Vendor will comply with its Information Security Program and represents and warrants that its Information Security Program is and will be in compliance with all applicable law. Vendor will deliver separate certifications of such compliance upon Company's reasonable request.
Vendor shall ensure that its personnel engaged in the Processing of Company Personal Data are informed of the confidential nature of the Company Personal Data, have received appropriate training on their responsibilities, and are subject to obligations of confidentiality, with such obligations surviving the termination of that individual's engagement with Vendor.
Vendor will take reasonable measures to cooperate and assist Company in conducting any required impact assessment and related consultations with any supervisory authority if Company is required to do so under Data Protection Laws.
To the extent Company, in its use or receipt of the products and/or services, does not have the ability to correct, amend, restrict, block or delete Company Personal Data as required by Data Protection Laws, Vendor shall promptly comply with reasonable requests by Company to facilitate such actions to the extent Vendor is able to do so.
Vendor shall promptly notify Company if it receives a request from a Data Subject for access to, correction, amendment, deletion of, or objection to the Processing of Company Personal Data relating to such individual. Vendor shall not respond to any such Data Subject request relating to Company Personal Data without Company's prior written consent except to confirm that the request relates to Company. Furthermore, Vendor shall, to the extent legally permitted, promptly notify Company if it receives a request for disclosure of or correspondence, notice or other communication relating to Company Personal Data from law enforcement, a competent authority, or a relevant data protection authority. Vendor shall provide Company with commercially reasonable cooperation and assistance in relation to handling of a Data Subject request.
In the event Vendor has actual or constructive notice of any actual or potential Security Breach, Vendor will take any necessary action to stop the active breach or similar recurring breaches and immediately (and in any event within forty-eight (48) hours):
(i) notify Company of the Security Breach and any third-party legal processes relating to the Security Breach at [email protected];
(ii) help Company investigate, remediate and take any other action Company deems necessary regarding the Security Breach and any dispute, inquiry, investigation or claim concerning the Security Breach; and
(iii) provide Company with sufficient information to allow Company to meet any obligations to report or inform Data Protection Authorities and/or Data Subjects of the Security Breach under the Data Protection Laws.
Such notification shall at a minimum:
In the event of a Security Breach, Company has the right to control the breach notification process, unless applicable law dictates otherwise.
In the event of a Security Breach, Vendor will be liable for any costs and expenses incurred by Company in connection with the Security Breach, including:
Subject to section 7.3, Vendor shall promptly and in any event within thirty (30) days of the date of cessation of any services involving the Processing of Company Personal Data (the "Cessation Date"), securely Delete all copies of any and all Company Personal Data from Vendor's data stores and ensure the Deletion of any and all Company Personal Data from the data stores of any sub-processors Vendor has utilized. For clarification, "Delete" means to remove or obliterate Personal Data such that it cannot be recovered or reconstructed.
Company may in its absolute discretion by written notice to Vendor within ten (10) business days of the Cessation Date require Vendor to provide a complete copy of any and all Company Personal Data from Vendor's data stores, to be provided to Company by secure file transfer in such format as is reasonably requested by Company. Such a request may include procurement of a complete copy of Company Personal Data from Vendor sub-processors.
Vendor may retain Company Personal Data to the extent required by applicable laws and only to the extent and for such period as required by applicable laws and always provided that Vendor shall ensure the confidentiality of all such Company Personal Data and shall ensure that such Company Personal Data is only Processed as necessary for the purpose(s) specified in the applicable laws requiring its storage and for no other purpose.
Vendor shall provide written certification to Company that it has fully complied with this Section 7 within thirty (30) days of the Cessation Date.
Taking into account the nature of the Processing and the information available to Vendor, Vendor will provide adequate reasonable cooperation and assistance to Company regarding Vendor's compliance obligations described in Articles 32-36 of the GDPR. Vendor shall make available to Company on reasonable request all information necessary to demonstrate compliance with this DPA and Data Protection Laws, and shall allow for and contribute to audits, including inspections, by Company or an auditor agreed to by the parties in relation to the Processing of the Company Personal Data. This provision serves to meet audit requirements pursuant to Article 28, Section 3(h) of the GDPR or any equivalent provision of applicable Data Protection Law.
Vendor will:
Company will bear the costs of such an audit, unless the audit reveals material vulnerabilities, in which case Vendor will cover the costs of the audit.
Vendor will not transfer, or cause to be transferred, any Company Personal Data from one jurisdiction to another unless in accordance with all applicable Data Protection Laws and will not cause Company to be in breach of any Data Protection Law.
To the extent, and only to the extent, Vendor Processes Company Personal Data from the European Economic Area and SCCs are required, Module Two of the EU SCCs shall apply and are hereby incorporated with the following specifics:
To the extent, and only to the extent, Vendor Processes Company Personal Data from the United Kingdom and SCCs are required, the UK Addendum to the EU SCCs will apply and is hereby incorporated.
To the extent, and only to the extent, Vendor Processes Company Personal Data from Switzerland, the following additional requirements shall apply to the extent the data transfers are exclusively subject to the FADP or are subject to both the FADP and the EU GDPR:
To the extent the Processing of Personal Data is subject to CCPA and CPRA:
To the extent, and only to the extent, Standard Contractual Clauses or Model Contractual Clauses are required under the applicable Data Protection Law, Vendor shall ensure the required clauses apply to its sub-processors.
To the extent, and only to the extent, there is a transfer of Company Personal Data other than those discussed above that requires country-specific SCCs or Model Contractual Clauses under the applicable Data Protection Laws, the parties agree that the appropriate required country-specific SCCs or Model Contractual Clauses are hereby automatically incorporated by reference and form an integral part of this DPA.
Vendor represents and warrants that:
In the event that services are covered by more than one transfer mechanism, the transfer of Company's Personal Data will be subject to a single transfer mechanism in accordance with the following order of precedence: (i) Vendor's Data Privacy Framework certification (if applicable); (ii) Vendor's Binding Corporate Rules (if applicable); (iii) Standard Contractual Clauses or Model Contractual Clauses (where required by applicable Data Protection Law).
Vendor will indemnify, defend, and hold harmless Company and its parent, subsidiaries, affiliates, agents and suppliers, and their respective officers, directors, shareholders and personnel, from and against any claims, suits, hearings, actions, damages, liabilities, fines, penalties, costs, losses, judgments or expenses (including reasonable attorneys' fees) arising out of or relating to Vendor's failure to comply with this DPA.
If Vendor can no longer meet its obligations under this DPA, it will immediately notify Company. Vendor will take reasonable and appropriate steps to stop and remediate, and will cooperate with Company's reasonable requests regarding, any unauthorized Processing of Company Personal Data by Vendor. A breach of any provision of this DPA may result in irreparable harm to Company, for which monetary damages may not provide a sufficient remedy, and therefore, Company may seek both monetary damages and equitable relief. Monetary damages for breach of the obligations in this DPA are not subject to any limitation of liability provision in the Agreement. In the event Vendor breaches any of its obligations under this DPA, Company will have the right to terminate the Agreement, or suspend Vendor's continued Processing of any Company Personal Data, without penalty immediately upon notice to Vendor.
This DPA will take effect on the date on which it is fully executed and, notwithstanding expiry of the term of any purchased subscription, remain in effect until, and automatically expire upon, deletion of all Company Personal Data as described in this DPA.
This DPA will be reviewed as appropriate under the circumstances.
Without prejudice to clauses 7 (Mediation and Jurisdiction) and 9 (Governing Law) of the Standard Contractual Clauses:
Company: Caliza, LLC d/b/a Landing
Privacy Contact: [email protected]
For questions regarding this Data Processing Addendum or data processing practices, please contact the privacy team at the email address above.
Note: This DPA includes references to Schedule 1 (Details of Processing of Company Personal Data) and Schedule 2 (Security Measures), which should be completed separately as part of the vendor agreement process.