Data Processing Addendum

Exhibit A – DATA PROCESSING ADDENDUM

This Data Processing Addendum (“DPA”) is incorporated into the Terms and Conditions by and between Origami Information Systems Ltd. (“Origami”) and you (meaning the individual or the entity, that the individual represents, that shall use the Services (“You” or “Your”). Origami and You will be referred to herein as the “Parties”. This DPA does not apply to Origami’s separate processing of data when it acts as a Controller, such as when Origami administers its business or contractual relationships, as further Described in Origami’s Privacy Policy.

WHEREAS, You have engaged Origami to provide the Services to You;

WHEREAS, the Services involves processing certain personal data, and the Parties wish to regulate Origami’s processing of such personal data, through this DPA, which is an integral part of the Terms and Conditions.

IN CONSIDERATION OF the mutual obligations set out herein, the Parties hereby agree that the terms and conditions set out below:

1. Definitions.

.1. “Data Protection Laws” means to the extent applicable to the Parties: (i) Regulation (EU) 2016/679 General Data Protection Regulation (“EU GDPR”); (ii) the UK Data Protection Act 2018, as well as the GDPR as it forms part of the law of England and Wales, Scotland and Northern Ireland by virtue of section 3 of the European Union (Withdrawal) Act 2018 and as amended by the Data Protection, Privacy and Electronic Communications (Amendments etc.) (EU Exit) Regulations 2019 (SI 2019/419) (“UK GDPR”); (iii) the California Consumer Privacy Act of 2018, the California Privacy Rights Act of 2020 and the regulations adopted thereunder Cal. Civ. Code §§ 1798.100 et. seq. and 11 C.C.R §§7000 et. seq. (“California Privacy Law”); (iv) Virginia Consumer Data Protection Act; (v) Colorado Privacy Act; (vi) Connecticut Act Concerning Personal Data Privacy and Online Monitoring; (vii) Utah Consumer Privacy Act; (vii) other state laws in the United States governing data protection, such as the Texas Data Privacy And Security Act (“TDPSA”); (ix) Israeli Privacy Protection Law, 5741-1981 and the regulations promulgated thereunder (and in particular the Privacy Protection Regulations (Information Security), 5777 – 2017))(“Israel Privacy Law”).

1.2. “Database” means a collection of Personal Data held by physical, magnetic or optical means.

1.3. “EU SCCs” means the Annex to Commission Implementing Decision (EU) 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council, available at https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj and incorporated by reference to this DPA.

1.4. “GDPR” means the EU GDPR and the UK GDPR.

1.5. “Sensitive Data” means Personal Data defined as “special categories of data” or other materially similar term under Data Protection Laws, including health data, genetic data, biometric data, information revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, sexual orientation or trade union membership.

1.6. “UK SCCs” means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses of 21 March 2022 issued under Section 119A of the UK Data Protection Act 2018, available at https://ico.org.uk/media/for-organisations/documents/4019539/international-data-transfer-addendum.pdf and incorporated by reference to this DPA.

1.7. The terms “Business”, “Business Purpose”, “Consumer”, “Collect”, “Sell”, “Share” and “Service Provider” will have the same meaning under California Privacy Law (Cal. Civ. Code §1798.140).

1.8. The terms “Personal Data”, “Controller”, “Processor”, “Data Subject”, “Personal Data Breach”, and “Processing” will have the same meaning as in the GDPR.

1.9. Capitalized terms used in this DPA but not defined herein have the meaning ascribed to them in in the Terms and Conditions.

2. Scope and responsibilities.

2.1. Without prejudice to any privacy, data protection or data security obligations under the Terms and Conditions, this DPA applies where Origami Processes Personal Data as a Processor or Service Provider on Your behalf of and under the Your instructions, where You are a Controller or Business under Data Protection Laws with respect to the Personal Data or Personal Information that Origami Processes. Whether You are a Controller or a Business under Data Protection Laws is determined according to the provisions of Data Protection Laws and not this DPA.

2.2. You and Origami are each responsible for complying with Data Protection Laws as applicable to them, in their roles as Controller or Business and Processor or Service Provider, respectively.

2.3. Origami will make available to You all reasonable information in its disposal necessary to demonstrate compliance with the obligations under the Data Protection Laws.

2.4. Origami will assist You with the preparation of data privacy impact assessments and prior consultation as appropriate, provided, however, that if such assistance entails material costs or expenses to Origami, the Parties will first come to agreement on You reimbursing Origami for such costs and expenses.

3. Specifics of Processing.

3.1. The particulars of Origami’s Processing activities as a Processor are specified in Appendix 1.

3.2. Origami will Process the Personal Data only on Your behalf and in the manner determined in the Terms and Conditions and this DPA, and for as long as You instruct Origami to do so, for the purpose of providing the Services to You. Origami will not Process the Personal Data for any other purpose, unless expressly instructed by You to do so. Origami may also engage in any other Processing activities that Data Protection Laws permit Service Providers or Processors to engage in.

3.3. Origami will Process the Personal Data on documented instructions from You, including without limitation through the Terms and Conditions and the Services’s features and functions configurable by You, unless Origami is otherwise required to by law to which it is subject (and in such a case, Origami will inform You of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest). Your instructions to Origami must be consistent with the nature of character of the Services. You are solely responsible for determining the lawfulness of the data processing instructions You provide to Origami and will provide Origami only instructions that are lawful under Data Protection Laws. Origami will immediately inform You if, in Origami ‘s opinion, an instruction is in violation the Data Protection Laws, or if Origami makes a determination that it can no longer meet its obligations under Data Protection Laws. In the event that any of Your instructions cause Origami to incur material incremental costs, Origami may notify You and, unless otherwise agreed upon by the Parties in a writing, such costs will be reimbursed by You.

3.4. To the extent You shall use the Service to process Sensitive Data, You must first obtain Origami’s explicit prior written consent. You shall not upload any Sensitive Data into the Service without such consent.

3.5. Origami deletes the Personal Data it has Processed on Your behalf under this DPA from its systems, after the end of the term of the Terms and Conditions or upon written request from You, and upon Your request, will furnish written confirmation that the Personal Data has been deleted pursuant to this section.

4. Data Subject rights.

4.1. You shall bear the sole and exclusive responsibility for complying with Data Subject and Consumer rights in the Personal Data, including accessing their data, correcting it, restricting its processing, or deleting it.

4.2. Taking into account the nature of Origami’s Processing activities and the Services, Origami will assist You to accommodate Data Subjects’ requests to exercise their rights in relation to their Personal Data.

4.3. When Origami received a request from a Data Subject or Consumer that it can identify as Your Data Subject or Consumer, Origami will pass on to You these requests.

5. Sub-processing.

5.1.1. You hereby extend Your general authorization to Origami to use third party sub-processors and service providers for Processing Personal Data within the scope of the Services. The current list of third party sub-processors and service providers is specified in Appendix 2 below. When required under the applicable Data Protection Laws, Origami will inform you in advance of any new or substitute third party sub-processors and service providers, in which case you shall have the right to object, on reasoned grounds, to that new or replaced third party sub-processors and service providers. If you so object, Origami may not engage that new or substitute third party sub-processors and service providers for the purpose of Processing Personal Data, and Origami may either select another third party sub-processors and service providers in which case the above procedure shall repeat, or if it so chooses, terminate the Terms and Conditions with you with no liability to you for such premature termination.

5.1.2. Origami will procure that the sub-processors Process the Personal Data in a manner consistent with Origami’s obligations under this DPA and Data Protection Laws, particularly Article 28 of the GDPR and 11 C.C.R. §7051, with such obligations imposed on that sub-processor by way of a written contract, in particular providing sufficient guarantees to implement appropriate technical and organizational measures in such a manner that the processing will meet the requirements of Data Protection Laws. Origami’s remains liable to You for the sub-processors’ compliance with their obligations.

6. Cross-border data transfers.

6.1. You acknowledge and agree that Origami and its sub-processors will only Process the Personal Data in member states of the European Economic Area, in territories or territorial sectors or organizations recognized by an adequacy decision of the European Commission as providing an adequate level of protection for Personal Data pursuant to Articles 45 of the GDPR, or using adequate safeguards as required under the GDPR’s provisions governing cross-border data transfers (e.g., SCCs).

6.2. Origami shall comply with Data Protection Laws applicable to cross-border transfer of Personal Data, including but not limited, to the Privacy Protection Regulations (Transfer of Information to Databases Outside of Israel), 5761-2001.

7. Data security.

7.1. Without prejudice to the data security obligations under the Terms and Conditions, in Processing Personal Data, Origami will implement appropriate technical and organizational measures to protect the Personal Data against accidental or unlawful destruction or accidental loss, alteration, unauthorized disclosure or access, as further described in Appendix 3.

7.2. Origami will perform regular internal or third-party assessments, audits, or other technical and operational testing of its security procedures and practices at least once every 12 months.

7.3. Origami will ensure that its staff authorized to Process the Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

7.4. Origami will without undue delay notify You of any Personal Data Breach that it becomes aware of regarding Personal Data of Data Subjects that Origami Processes within the scope of this DPA. Origami’s notification to You will include the following information, as well as other information reasonably requested by You, and if the information is not readily available at the time of the notification or request by You, Origami may provide it in phases as it becomes available:

7.4.1. The nature of the Personal Data Breach including where possible, the categories and approximate number of Data Subjects and Consumers concerned and the categories and approximate number of Personal Data records concerned;

7.4.2. The likely consequences of the Personal Data Breach; and

7.4.3. The measures taken or proposed to be taken to address the Personal Data Breach, including, where appropriate, measures to mitigate its possible adverse effects.

7.5. Origami will use commercial efforts to mitigate a Personal Data Breach and prevent its recurrence. You and Origami will cooperate in good faith on issuing any statements or notices regarding such Personal Data Breaches, to authorities, Data Subjects and Consumers.

8. Audits.

8.1. Origami will, not more than once per annum (unless otherwise required by a data protection authority or Data Protection Law), allow for and contribute to audits, including carrying out inspections conducted by a reputable auditor mandated by You, during normal business hours and subject to a prior notice to Origami of at least 30 days and coordination with Origami as to the agenda of the audit, as well as appropriate confidentiality undertakings by the auditor covering such inspections, in order to establish Origami’s compliance with this DPA and the provisions of the Data Protection Laws regarding the Personal Data that Origami Processes on behalf of You. Such audits and inspection must reasonably limit any disruption to Origami’s business, and You will avoid (and ensure that each of its auditors avoids) causing (or, if it cannot avoid, minimize) any damage, injury or disruption to Origami’s premises, equipment, personnel, and business while its personnel are on those premises during such audit or inspection. If such audits or inspections entail material costs or expenses to Origami, the Parties will first come to agreement on You reimbursing Origami for such costs and expenses.

9. Return or deletion of information.

Upon your written request where no subsequent further processing is required, Origami shall, at your instruction, either delete, destroy or return to you, some or all (however instructed) of the of the Personal Information that Origami Process on your behalf. Upon your request, Origami will furnish written confirmation that the Personal Data has been deleted or returned pursuant to this section.

10. Disclosure.

Unless legally prohibited, Origami will provide you with prompt notice of any request it receives from authorities to produce or disclose Personal Data it has Processed on your behalf, so that you will be able to contest or attempt to limit the scope of production or disclosure request.

11. California Privacy Law.

This section 9 applies to the extent that You are a Business subject to the California Privacy Law.

11.1. The Parties acknowledge and agree that Origami is a Service Provider.

11.2. The Parties agree that You are disclosing the Personal Information to Origami only for the following limited and specified Business Purpose: the provision of Origami’s Services. Origami will not Sell or Share the Personal Information.

11.3. Origami is prohibited from retaining, using, or disclosing Your Personal Information for:

11.3.1. Any commercial purpose other than the foregoing Business Purposes, unless expressly permitted by the California Privacy Law.

OR

11.3.2. Outside the direct business relationship between You and Origami, unless expressly permitted by the California Privacy Law.

11.4. Origami will comply with all applicable sections of the California Privacy Law.

11.5. Origami grants You the right to take reasonable and appropriate steps, in accordance with this DPA, to ensure that the Origami uses the Personal Information it Collects pursuant to this DPA in a manner consistent with Origami ‘s obligations under the California Privacy Law.

11.6. Origami grants You the right, upon notice, to take reasonable and appropriate steps, in accordance with this DPA, to stop and remediate Origami’s unauthorized use of Personal Information.

11.7. If Origami receives a request from a California Consumer, about his or her Personal Information processed by You, Origami will inform You thereof, will not comply with the request itself unless instructed to in writing by You, and in the absence of Your instructions to the contrary, will inform You that the request cannot be acted upon because the request has been sent to a Service Provider.

12. Israel Privacy Law.

Appendices 4,5 and 6 of this DPA will apply to the extent that You are subject to the Israel Privacy Law.

13. Miscellaneous.

13.1. Origami’s liability under this DPA will be as per the limitations, exclusions and caps specified in the Terms and Conditions.

13.2. This DPA will prevail in the event of inconsistencies between it and the Terms and Conditions or subsequent agreements entered into or purported to be entered into by the Parties after the date of this DPA, except where explicitly agreed otherwise in writing.


13.3. This DPA is governed by the governing law specified in the Agreement, and disputes arising under this DPA will be adjudicated as specified in the Terms and Conditions.

13.4. This DPA terminates upon the termination of the Terms and Conditions.

13.5. All the clauses in the DPA that are bound by and required under Data Protection Laws, will continue to apply even after the expiration or termination of the Terms and Conditions between the Parties, provided that Origami continues to retain Your Personal Data

Appendix 1 – Details of Processing

1. Categories of Data Subjects

As determined and controlled by You in Your sole discretion.

2. Categories of Personal Data Processed

The type and extent of Personal Data uploaded by You into the Services, shall be determined and controlled by You in Your sole discretion.

3. Special categories of Personal Data Processed

The type and extent of special categories of Personal Data uploaded by You into the Services, shall be determined and controlled by You in Your sole discretion.

4. Frequency of Transfer

Ongoing, throughout the term of the Terms and Conditions.

5. Nature of the Processing

Retrieval, organization, structuring, storage, adaptation or alteration, combination.

6. Purpose(s) of the Data Transfer

The provision of the Services as specified in the Purchase Order attached to the Terms and Conditions.

7. The Period for Which the Personal Data Will Be Retained

The retention period is coterminous with the term of the Terms and Conditions and to Your instructions to cease and discontinue Processing.

8. Transfers to Sub-Processors

See Appendix 2.

Appendix 2 – List of Sub-processors

Name of Sub-processorSubject matter/nature of processingSub- processor regionDuration of Processing
Google Cloud PlatformHosting infrastructure and data storage servicesEUThe duration of the Terms and Conditions
Microsoft AzureCloud computing services including data hosting, computing, and analyticsEUThe duration of the Terms and Conditions
Atlas-MongoDBDatabase management services to host and manage application dataEUThe duration of the Terms and Conditions
Amazon S3Cloud-based storage services for scalable and secure web server storageEUThe duration of the Terms and Conditions

Appendix 3 – Technical and Organizational Measures

Certifications: Origami is certified with ISO 9001 and ISO 27001:2013, granted by the Standards Institute of Israel.

AWS and Azure Infrastructure: Origami employs AWS’s and Azure infrastructure, which includes biometric authentication for all data centers.

Data Encryption: All data is encrypted during transit, and encryption at rest is also available.

Secure Sockets Layer (SSL) Encrypted Communication: SSL certificates protect server-client communication, ensuring all information transmitted is encrypted.

User Access Controls: Origami offers an extensive permissions management system, allowing administrators to define what each user can see and do, following the principle of least privilege.

Multi-Factor Authentication (MFA) and Single Sign-On (SSO): Origami supports MFA and SSO from active directories or other identification systems, providing an additional layer of security by verifying user identities.

IP-Based Access Restriction: Origami allows administrators to control access to Origami based on IP addresses. This means that only users accessing Origami from predefined IP addresses can log in.

Web Application Firewall (WAF) and Server Firewall: Our WAF proactively protects Origami from fraud and data theft, blocking suspicious activity. It inspects every web request for potential threats such as cross-site scripting, SQL injection, path traversal, and over 400 other types of attack. Additionally, our server firewalls create a highly controlled access point, limiting access based on specific IPs, specific ports, passwords, OTPs, and more.

Endpoint Protection: All endpoints are equipped with Endpoint Detection and Response (EDR) and anti-malware software, with restrictions on installing additional software, ensuring physical hardware is equally protected.

Regular Backups and Automated Disaster Recovery System: Orogami performs three daily backups, providing over 90 restore points at any given time. This ensures rapid recovery in case a backup is needed. Moreover, in the event of a disaster, our automated recovery system restores all critical functions quickly and with minimal disruption, ensuring business continuity.

Regular Security Audits and Penetration Testing: Origami conducts regular security audits and annual penetration testing to identify and address any potential vulnerabilities.

Employee Training: Origami’s team is regularly trained to identify and avoid potential threats such as phishing and social engineering, reducing the risk of human error.

Appendix 4 – Additional requirements for Databases subject to Israel Privacy Law

1. Origami shall grant its employees access to the Database, subject to conducting training activities regarding privacy protection and information security obligations applicable to Origami by virtue of the Data Protection Laws and this DPA.

2. Origami shall not grant access to the Personal Data to its employees, before reviewing and confirming, within the boundaries of applicable law, that their background, integrity, and reliability are suitable for a position granting them access to Personal Data.

3. Origami undertakes to manage access rights to Personal Data, including by way of providing its employees with ‘Least Privileges’ based on their ‘Need to Know’, for the purpose of carrying out their tasks, and shall take measures in order prevent access by unauthorized individuals to Personal Data. In addition, Origami will maintain an up-to-date listing of all individuals authorized to access or use the Database and will prevent access to any individual who does not have a need to be exposed to the Personal Data.

Origami shall develop, implement, and enforce an information security policy that covers at least the following topics (“Information Security Policy”):

4.1 Guidelines regarding the physical protection of the Database systems and the sites in which they are located;

4.2 Guidelines regarding the management and monitoring of access authorizations and actions taken in the Database;

4.3 Mapping of all the of the security measures taken by Origami regarding the Database;

4.4 Guidelines for individuals authorized to access Personal Data and Database;

4.5 A review of the risks to which the Personal Data is exposed to as part of Origami’s ongoing activities including instructions regarding the means of recording, monitoring, and identifying threats to which the Database systems are exposed;

4.6 Instructions and procedures regarding the mitigation and management of a Personal Data Breach;

4.7 Instructions and procedures regarding the use of removable devices.

5. Origami shall map the operational environment of the Database. In this regard, Origami shall prepare an inventory list that includes all the systems, software, interfaces, infrastructures of hardware components and communications components that Origami operates in the Database environment for the ongoing operation of the Database (the “Database Systems”). Origami shall update the list of inventories specified in this section from time to time and shall only disclose the document to those individuals who require access to it for the performance of their job functions. However, Origami shall update the foregoing list in any case in which substantial changes to the operating environment are implemented in the Database or in the manner in which Personal Data is Processed.

6. In the event of a Personal Data Breach, Origami will provide a notification to You no later than twenty-four (24) hours after becoming aware of any Personal Data Breach.

7. If required by Data Protection Laws, Origami shall provide You, at least in every 12 month or upon its request, a written approval according to which it performs and fulfills its obligations pursuant to this DPA and the provisions of the Data Protection Laws. Origami shall fully cooperate with You in providing all information and assistance reasonably requested by You in connection with data security issues and practices and supplementary documents, so as to allow You to properly address information security, privacy and regulatory matters relating to the Database.

8. To the extent that Your Database is considered a Database at medium data security level under Israel privacy Law, this Database will be subject to additional requirements as set forth in Appendix 5 of this DPA.

9. To the extent that the Your Database is considered a Database at high data security level under Israel privacy Law, this Database will be subject to additional requirements as set forth in Appendices 5 and 6 of this DPA.

Appendix 5 – Additional requirements for Databases at medium data security level under Israel Privacy Law

1. Without derogating from section 4 of Appendix 4 above, Origami shall include in the Information Security Policy the following:

1.1 The means of identification and verification of access the Database Systems;

1.2 Instructions regarding the manner in which access to the Database is managed, the means of controlling access to Personal Data and the actions taken regarding the Personal Data.

1.3 Instructions regarding periodic audit reports as stated in section 8 of the DPA above.

1.4 Instructions and procedures regarding periodic backup and restoration of the Documentation Mechanism (defined below);

1.5 Instruction regarding the manner in which development activities in the Database are performed and documented;

3. In addition to the requirements set in section 5 of Appendix 4 above, Origami will ensure that the systems and devices located in its premises or assigned to its employees, consultants, and anyone on its behalf, on which Personal Data is Processed or accessed (for example: servers, workstations, communication components, etc.) will be stored in a protected location, which prevents unauthorized intrusion and physical entry. Without derogating from the above, Origami will take measures to control and document the entry to and exit from its own sites where the Database Systems are located, and will audit all inbound and outbound equipment to and from the Database Systems (for example: laptops, laptops, cameras, etc.).

4. Without derogating from section 1 of Appendix 4 above, Origami shall grant its employees with access to the Database, subject to conducting training activities regarding privacy protection and information security obligations applicable. Such training shall take place at least once every two years and as soon as possible after recruiting.

5. Origami shall grant its own authorized users with access to the Database subject to authentication measures based on physical means, such as two-factor authentication through the smartphone of the authorized user. In this regard, Origami shall determine the means of identification, instructions related to passwords management, automatic disconnection from the Database after period of inactivity (idle time), and provisions regarding how to handle faults related to identity authentication.

6. Origami undertakes to automatically document all activities carried out in the Database Systems, including (but not limited to) documenting attempts to access the database systems, deleting and/or changing Personal Data, database development operations and change in access permissions to the database systems (“Documentation Mechanism”). The Documentation Mechanism will collect at least the following data: the user’s identity, the date and time of the operation, the source of the operation (web address or computer name), the system component in which the operation was performed, the type of operation, whether the operation was successful or failed. The audit data generated by the Documentation Mechanism shall be maintained for 24 months.

7. Without derogating from section 6 of Appendix 4 above, Origami will discuss occurrences of Personal Data Breaches at least once every 12 months, and will examine the need to update its Information Security Policy as a result therefrom. The findings of those discussions will be sent to You.

8. Origami undertakes to conduct, at least once in 24 months, an internal or external audit by an entity or a person with appropriate certification for auditing information security (who is not the Origami’s CISO), in order to ascertain the Origami’s compliance with these provisions and the provisions of Data protection Laws.

9. Origami undertakes to establish guidelines regarding how to recover and backup the Personal Data periodically including instructions regarding data recovery during Personal Data Breach.

Appendix 6 – Additional requirements for Databases at high data security level under Israel Privacy Law

1. In addition to the requirements specified in section 4 of Appendix 4 above, Origami shall conduct data security risk assessments, in relation to its Processing of Your Personal Data in accordance with the Terms and Conditions and this DPA. Such data protection risk assessment will take place at least every eighteen (18) months.

2. In addition to the requirements specified in section 4 of Appendix 4 above, Origami shall conduct penetration tests on the Database Systems to examine their resilience to internal and external risks. Such tests shall take place at least once every eighteen (18) months; Origami will then discuss the results of the penetration tests and will correct the deficiencies discovered (in any). The findings will be shared with You.

3. Notwithstanding Section 7 of the DPA above, Origami will conduct discussions regarding occurrence of Personal Data Breaches at least every three (3) months and will examine the need to update its Information Security Policy. The findings will be shared with You.

4. Without derogating from section 9 of Appendix 4 above, Origami will maintain a copy of the backup data in a manner that assures the accuracy and reliability of that data.