Data Sharing Addendum Archive
DATA SHARING ADDENDUM
Version: June 25, 2025
This Data Sharing Addendum (“Addendum”) forms a part of the Civitas Learning, Inc. (“Civitas”) Master Services Agreement (“MSA”) governed the provision of Civitas products and services. By entering into an Order Form subject to the MSA, Customer agrees to be bound by the terms of this Addendum.
The terms used in this Addendum shall have the meanings set forth in this Addendum. Capitalized terms not otherwise defined herein shall have the meaning given to them in the MSA. Except as modified below, the terms of the MSA shall remain in full force and effect.
In consideration of the mutual obligations set out herein, the Parties hereby agree that the terms and conditions set out below shall be added as an Addendum to the MSA. Except where the context requires otherwise, references in this Addendum to the MSA are to the MSA as amended by, and including, this Addendum.
- Definitions
In this Addendum, the following terms shall have the meanings set out below and cognate terms shall be construed accordingly:
1.1 “Applicable Laws” means to the extent applicable, the laws and regulations of any country relating to the Shared Personal Data, including but not limited to all Data Protection Laws. For the avoidance of doubt, nothing in this Addendum shall be construed as a representation that either Party is subject to any Applicable Law.
1.2 “Affiliate” means, with respect to a Party, any entity that directly or indirectly controls, is controlled by, or is under common control with such Party, whereby “control” (including, with correlative meaning, the terms “controlled by” and “under common control”) means the possession, directly or indirectly, of the power to direct, or cause the direction of the management and policies of such person, whether through the ownership of voting securities, by contract, or otherwise.
1.3 “Business Day” means a day, other than a Saturday, Sunday, or public holiday, on which clearing banks are open for non-automated commercial business in City of Austin, Texas.
1.4“Contracted Processor” means any Processor or Service Provider, as those terms are defined under Data Protection Laws) (excluding Civitas employees) appointed by Civitas to Process Shared Personal Data in connection with this Addendum or the MSA.
1.5“Data Protection Laws” means, insofar as any Party is subject thereto relating to the Shared Personal Data, and all as amended, replaced, or superseded from time to time:
- 1.5.1The Family Educational Rights and Privacy Act (“FERPA”), including any regulations promulgated thereunder,
- 1.5.2 The Gramm-Leach-Bliley Act (“GLBA”), including any regulations promulgated thereunder; and
- 1.5.3 The EU General Data Protection Regulation 2016/679 (“GDPR”), as transposed into domestic legislation of each member state of the EU;
- 1.5.4 The UK General Data Protection Regulation (“UK GDPR”) and the UK Data Protection Act 2018, including any applicable regulations promulgated thereunder;
- 1.5.5Collectively, all U.S. State omnibus data protection laws, including any applicable regulations promulgated thereunder; and
- 1.5.6Any other applicable data protection or privacy laws and any amendments or successors thereto, including but not limited to federal, state, or other international laws or regulations.
1.6 “Data Subject” means an identified or identifiable natural person.
1.7 “Parties” means the Parties to this Addendum, namely Civitas and Customer.
1.8 “Personal Data” means any information that identifies, relates to, describes, is capable of being associated with, or could reasonably be linked, directly or indirectly, to a Data Subject. Personal Data does not include data that has been anonymized, de-identified, or aggregated such that Data Subjects are not individually identifiable.
1.9 “Shared Personal Data” means any Personal Data transferred by Customer to Civitas, including Personal Data collected by Civitas from a third-party on behalf of Customer, and any derived Personal Data transferred by Civitas to Customer pursuant to this Addendum or in connection with MSA, including but not limited to student education record information subject to FERPA.
1.10 “Personal Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, the Shared Personal Data.
1.11“Processing” means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
1.12 “Regulatory Authority” means any public authority, or government agency responsible for exercising authority over the Shared Personal Data, or the Parties’ processing thereof.
1.13 “Tracking Technology” means technology that causes information to be stored by or collected from any digital device including, but not limited to, scripts, cookies, tags, pixels, or other similar tracking technologies.
The word “include” shall be construed to mean include without limitation, and cognate terms shall be construed accordingly.
2 Purposes of this Addendum
- 2.1This Addendum sets out the framework for the sharing and Processing of Personal Data between the Parties as joint Controllers of the Shared Personal Data and defines the principles and procedures that the Parties shall adhere to, the rights of the Parties, and the responsibilities the Parties owe to each other.
- 2.2The Parties agree that this Addendum formalizes a lawful transfer of Personal Data between the Parties, and that Civitas qualifies under FERPA as a “school official” of Customer whom the Customer has determined has a legitimate educational interest in the Processing of Shared Personal Data.
- 2.3 The Parties recognize that the sharing of Personal Data is necessary to achieve the purposes of the MSA, and that the Parties shall not process Shared Personal Data in a way that is incompatible with the MSA or this Addendum. Civitas further agrees to abide by the limitations on re-disclosure of education records from the Shared Personal Data set forth in FERPA.
3. Compliance with Laws
- 3.1 Each Party agrees to comply with all Applicable Laws at all times in accordance with this Addendum and agrees that Processing under this Addendum shall only occur with a valid legal basis under any such Applicable Laws.
4. Permitted Recipients
- 4.1In the context of Processing data pursuant to this Addendum, the Shared Personal Data may only be accessed by the Parties to this Addendum, employees and agents of each Party, the Data Subject to which the Shared Personal Data pertains, and any Contracted Processor in connection with this Addendum, subject to requirements of this Addendum.
- 4.2Civitas shall implement procedures so that any third party it authorizes to have access to the Shared Personal Data, including Contracted Processors, will respect and maintain the confidentiality and security of the Shared Personal Data. Any person acting under the authority of the Civitas, including a Contracted Processor, shall be obligated to process the Shared Personal Data only on instructions from Civitas. This provision does not apply to persons authorized or required by Applicable Laws to have access to the Shared Personal Data.
- 4.3 Neither Party shall use, share, sell, rent, release, disclose, disseminate, make available, transfer, or otherwise communicate orally, in writing, or by electronic or any other means, any Shared Personal Data to another business or third party for monetary or other valuable consideration that qualifies as a “Sale” of the Shared Personal Data under Applicable Laws.
5. Shared Personal Data
- 5.1The Parties recognize that while the Civitas requires certain types of Personal Data to effectively deliver the Services under the MSA, Customer shall have ultimate control over which types of Personal Data are transferred to or accessed by Civitas. As contemplated herein, the following types of Personal Data may be shared between the Parties:
- 5.1.1 Students and Faculty Data: First and last name, contact information (email, phone, physical business address), identification data (ID numbers, usernames, aliases, etc.), and device data (connection data, location data, etc.).
- 5.1.2 Student Only Data: Physical characteristics data (ethnicity, gender, religion, sex), family data (family member information, socioeconomic status, etc.), and educational data (class schedules, academic records, etc.).
- 5.2.2 Faculty and Staff Only Data: Professional data (employer, title, etc.).
6. Data Quality
- 6.1 Customer shall use its best efforts to ensure that Shared Personal Data provided to Civitas is accurate and current. Where Customer becomes aware of inaccuracies in Shared Personal Data, Customer shall promptly notify Civitas in writing of such inaccuracies.
7. Data Subject Rights
-
7.1 The Parties acknowledge student Data Subjects’ right to inspect and review their academic records under FERPA and shall endeavor to provide access to such educational records within the Shared Personal Data if properly requested by a student Data Subject in compliance with FERPA.
-
7.2 The Parties agree that the responsibility for responding to a request from a Data Subject regarding Shared Personal Data under any Data Protection Law falls to Customer.
-
7.3 Taking into account the nature of the Processing, Civitas shall assist Customer by implementing appropriate technical and organizational measures, insofar as this is possible, to enable the fulfillment of Customer’s obligations, as reasonably understood by Customer, to respond to requests to exercise Data Subject rights under the Data Protection Laws.
-
7.4Civitas shall:
- 7.4.1notify Customer within three (3) Business Days if Civitas receives a request from a Data Subject, either directly or from a Contracted Processor, under any Data Protection Law regarding Shared Personal Data;
- 7.4.2 not respond to any such Data Subject request except as required by Applicable Laws to which the Civitas is subject, in which case Civitas shall to the extent permitted by Applicable Laws inform Customer of that legal requirement before responding to the request.
-
7.5 Customer shall:
- 7.5.1 promptly notify Civitas of any Data Subject requests received by Customer related to Civitas’s services provided under the MSA or the Shared Personal Data exchanged under this Addendum;
- 7.5.2obtain all necessary consents from Data Subjects, in writing, to the extent consent is required by Applicable Laws in order to authorize Civitas (through the Services) to communicate with Data Subjects on behalf of Customer, including but not limited to communications made via telephone, SMS message, email, push notifications, Tracking Technologies, or similar means, with or without the use of automated dialing technology; and
- 7.5.3 promptly notify Civitas of changes to or revocations of any Data Subject consents referred to in Section 7.5.2.
8. Security
- 8.1The Parties agree to implement appropriate administrative, physical, and technical safeguards to protect Shared Personal Data from unauthorized access, acquisition, disclosure, destruction, alteration, accidental loss, misuse, or damage that are no less rigorous than applicable industry standards for information security, and shall ensure that all such safeguards, including the manner in which Shared Personal Data is created, collected, accessed, received, used, stored, processed, disposed of, and disclosed, comply with Applicable Laws, as well as the terms and conditions of this Addendum.
- 8.2 Civitas’s safeguards for the protection of the Shared Personal Data shall include: (i) limiting access of Shared Personal Data to persons authorized to access such data; (ii) securing business facilities, data centers, paper files, servers, backup systems, and computing equipment, including, but not limited to, all mobile devices and other equipment with information storage capability; (iii) implementing network, application, database, and platform security; (iv) securing information transmission, storage, and disposal; (v) implementing authentication and access controls within media, applications, operating systems, and equipment; (vi) conducting risk assessments, penetration testing, and vulnerability scans; (vii) implementing appropriate personnel security and integrity procedures and practices, including, but not limited to, conducting background checks consistent with applicable law; and (viii) providing appropriate privacy and information security training to employees.
9. Personal Data Breach
- **9.1.**In the event of a Personal Data Breach, responsibility for reporting the breach to Regulatory Authorities falls to the Party suffering the breach of security leading to the Personal Data Breach, unless Applicable Laws require otherwise.
- **9.2.**Civitas shall promptly notify Customer upon Civitas becoming aware of a Personal Data Breach affecting Shared Personal Data, and at that time shall provide Customer with information to allow Customer to meet any obligations to report or inform Data Subjects of the Personal Data Breach under the Data Protection Laws. Such notification shall:
- 9.2.1 describe the nature of the Personal Data Breach, the categories and numbers of Data Subjects concerned, and the categories and numbers of Personal Data records concerned;
- 9.2.2 communicate the name and contact details of Civitas’s data protection officer or other relevant contact from whom more information may be obtained;
- 9.2.3 describe the likely consequences of the Personal Data Breach; and
- 9.2.4describe the measures taken or proposed to be taken to address the Personal Data Breach,
provided that, (without prejudice to the above obligations) if Civitas cannot provide all these details within the timeframes set out in this Section, it shall (before the end of such timeframes) provide Customer with the reasons for the delay, and when it expects to be able to provide the relevant details (which may be provided in phases), and give Customer regular updates on these matters.
- 9.3Customer shall promptly notify Civitas upon Customer becoming aware of a Personal Data Breach affecting or resulting in actual or suspected compromise of Civitas’s information technology assets, resources, services, or systems.The Parties agree to provide reasonable assistance as is necessary to each other to facilitate the handling of any Personal Data Breach in an expeditious and compliant manner.
10. Data Protection Cooperation
- 10.1The Parties agree to provide one another with reasonable cooperation and assistance as requested by either Party in relation to any compliance measure which the Parties reasonably consider to be required by Data Protection Laws in relation to the Processing of the Shared Personal Data.
- 10.2A Party may provide notice to the other Party of any variations to this Addendum which a Party reasonably considers to be necessary to address the requirements of any Data Protection Law.
- 10.3 If a Party gives notice under the foregoing Section, the Parties shall promptly discuss the proposed variations and negotiate in good faith with a view to agreeing and implementing those or alternative variations designed to address the requirements identified in the proposing Party’s notice as soon as is reasonably practicable.
11. Indemnification
- 11.1 Any breach of the Data Protection Laws, or of either Parties’ obligations under this Addendum, shall be governed by the MSA.
12. Warranties
- 12.1 Each Party warrants and undertakes to the other Party that:
- 12.1.1 it has the right, power and authority to enter into this Addendum and to perform its obligations under this Addendum;
- 12.1.2 to its knowledge there are no threatened or pending or actual court or regulatory actions, suits, or proceedings against or affecting that Party that might affect the ability of that Party to meet and carry out its obligations under this Addendum;
- 12.1.3 it is able to perform all of its obligations under this Addendum; and
- 12.1.4 entering this Addendum will not cause that Party to be in breach of any other contract to which it is a Party or to be in breach of any statutory or other legal requirement.
13. General Terms
Governing law and jurisdiction
- 13.1 The Parties to this Addendum hereby submit to the choice of jurisdiction stipulated in the MSA with respect to any disputes or claims howsoever arising under this Addendum, including disputes regarding its existence, validity or termination or the consequences of its nullity.This Addendum and all non-contractual or other obligations arising out of or in connection with it are governed by the laws of the country or territory stipulated for this purpose in the MSA.
Order of precedence
- 13.2In the event of inconsistencies between the provisions of this Addendum and any other agreements between the Parties, including the MSA and including (except where explicitly agreed otherwise in writing signed on behalf of the Parties) agreements entered into or purported to be entered into after the date last signed by the Parties, the provisions of this Addendum shall prevail.
Severance
- 13.3 Should any provision of this Addendum be invalid or unenforceable, then the remainder of this Addendum shall remain valid and in force. The invalid or unenforceable provision shall be either (i) amended as necessary to ensure its validity and enforceability, while preserving the Parties’ intentions as closely as possible or, if this is not possible, (ii) construed in a manner as if the invalid or unenforceable part had never been contained therein.
By entering into an Order Form, Customer agrees that this Addendum is entered into and becomes a binding part of the MSA as of the MSA Effective Date, thereafter terminating upon the cessation of Processing under this Addendum.
DATA SHARING ADDENDUM
Version: March 12, 2024
This Data Sharing Addendum (“Addendum”) forms a part of the Civitas Learning, Inc. (“Civitas”) Master Services Agreement (“MSA”) governed the provision of Civitas products and services. By entering into an Order Form subject to the MSA, Customer agrees to be bound by the terms of this Addendum.
The terms used in this Addendum shall have the meanings set forth in this Addendum. Capitalized terms not otherwise defined herein shall have the meaning given to them in the MSA. Except as modified below, the terms of the MSA shall remain in full force and effect. In consideration of the mutual obligations set out herein, the Parties hereby agree that the terms and conditions set out below shall be added as an Addendum to the MSA. Except where the context requires otherwise, references in this Addendum to the MSA are to the MSA as amended by, and including, this Addendum.
1. Definitions
In this Addendum, the following terms shall have the meanings set out below and cognate terms shall be construed accordingly:
1.1 **“Applicable Laws”**means to the extent applicable, the laws and regulations of any country relating to the Shared Personal Data, including but not limited to all Data Protection Laws. For the avoidance of doubt, nothing in this Addendum shall be construed as a representation that either Party is subject to any Applicable Law.
1.2 “Affiliate” means, with respect to a Party, any entity that directly or indirectly controls, is controlled by, or is under common control with such Party, whereby “control” (including, with correlative meaning, the terms “controlled by” and “under common control”) means the possession, directly or indirectly, of the power to direct, or cause the direction of the management and policies of such person, whether through the ownership of voting securities, by contract, or otherwise.
1.3 “Business Day” means a day, other than a Saturday, Sunday, or public holiday, on which clearing banks are open for non-automated commercial business in City of Austin, Texas.
1.4 “Contracted Processor” means any Processor (excluding Civitas employees) appointed by Civitas to Process Shared Personal Data in connection with this Addendum or the MSA.
1.5 “Data Protection Laws” means:
1.5.1 The Family Educational Rights and Privacy Act (“FERPA”), including any regulations promulgated thereunder, and as amended, replaced, or superseded from time to time;
1.5.2 The Gramm-Leach-Bliley Act (“GLBA”), including any regulations promulgated thereunder, and as amended, replaced, or superseded from time to time; and
1.5.3 The EU General Data Protection Regulation 2016/679 (“GDPR”), as transposed into domestic legislation of each member state of the EU and as amended, replaced or superseded from time to time; and
1.5.4 Any other applicable data protection or privacy laws and any amendments or successors thereto, including but not limited to federal, state, or other international laws or regulations.
1.6 “Data Subject” means an identified or identifiable natural person.
1.7 “Parties” means the Parties to this Addendum, namely Civitas and Customer.
1.8 “Personal Data” means any information that identifies, relates to, describes, is capable of being associated with, or could reasonably be linked, directly or indirectly, to a Data Subject. Personal Data does not include data that has been anonymized, de-identified, or aggregated such that Data Subjects are not individually identifiable.
1.9 “Shared Personal Data” means any Personal Data transferred by Customer to Civitas, including Personal Data collected by Civitas from a third-party on behalf of Customer, and any derived Personal Data transferred by Civitas to Customer pursuant to this Addendum or in connection with MSA, including but not limited to student education record information subject to FERPA.
1.10 “Personal Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, the Shared Personal Data.
1.11 “Processing” means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
1.12 “Controller” means the natural or legal entity or entities who alone or jointly exercise control over the purposes and the means of the Processing of Shared Personal Data.
1.13 “Regulatory Authority” means any public authority, or government agency responsible for exercising authority over the Shared Personal Data, or the Parties’ processing thereof.
1.14 “Processor” means a natural or legal person which processes personal data on behalf of the controller. The word “include” shall be construed to mean include without limitation, and cognate terms shall be construed accordingly.
2. Purposes of this Addendum
2.1 This Addendum sets out the framework for the sharing and Processing of Personal Data between the Parties as joint Controllers of the Shared Personal Data and defines the principles and procedures that the Parties shall adhere to, the rights of the Parties, and the responsibilities the Parties owe to each other.
2.2 The Parties agree that this Addendum formalizes a lawful transfer of Personal Data between the Parties, and that Civitas qualifies under FERPA as a “school official” of Customer whom the Customer has determined has a legitimate educational interest in the Processing of Shared Personal Data.
2.3 The Parties recognize that the sharing of Personal Data is necessary to achieve the purposes of the MSA, and that the Parties shall not process Shared Personal Data in a way that is incompatible with the MSA or this Addendum. Civitas further agrees to abide by the limitations on re-disclosure of education records from the Shared Personal Data set forth in FERPA.
3. Compliance with Laws
3.1 Each Party agrees to comply with all Applicable Laws at all times in accordance with this Addendum and agrees that Processing under this Addendum shall only occur with a valid legal basis under any such Applicable Laws.
4. Permitted Recipients
4.1 In the context of Processing data pursuant to this Addendum, the Shared Personal Data may only be accessed by the Parties to this Addendum, employees and agents of each Party, the Data Subject to which the Shared Personal Data pertains, and any Contracted Processor in connection with this Addendum, subject to requirements of this Addendum.
4.2 Civitas shall implement procedures so that any third party it authorizes to have access to the Shared Personal Data, including Contracted Processors, will respect and maintain the confidentiality and security of the Shared Personal Data. Any person acting under the authority of the Civitas, including a Contracted Processor, shall be obligated to process the Shared Personal Data only on instructions from Civitas. This provision does not apply to persons authorized or required by Applicable Laws to have access to the Shared Personal Data.
5. Shared Personal Data
5.1 The Parties recognize that while the Civitas requires certain types of Personal Data to effectively deliver the Services under the MSA, Customer shall have ultimate control over which types of Personal Data are transferred to or accessed by Civitas. As contemplated herein, the following types of Personal Data may be shared between the Parties:
5.1.1 Students and Faculty Data: First and last name, contact information (email, phone, physical business address), identification data (ID numbers, usernames, aliases, etc.), and device data (connection data, location data, etc.).
5.1.2 Student Only Data: Physical characteristics data (ethnicity, gender, religion, sex), family data (family member information, socioeconomic status, etc.), and educational data (class schedules, academic records, etc.).
5.1.3 Faculty and Staff Only Data: Professional data (employer, title, etc.).
6. Data Quality
6.1 Customer shall use its best efforts to ensure that Shared Personal Data provided to Civitas is accurate and current. Where Customer becomes aware of inaccuracies in Shared Personal Data, Customer shall promptly notify Civitas in writing of such inaccuracies.
7. Data Subject Rights
7.1 The Parties acknowledge student Data Subjects’ right to inspect and review their academic records under FERPA and shall endeavour to provide access to such educational records within the Shared Personal Data if properly requested by a student Data Subject in compliance with FERPA.
7.2 The Parties agree that the responsibility for responding to a request from a Data Subject regarding Shared Personal Data under any Data Protection Law falls to Customer.
7.3 Taking into account the nature of the Processing, Civitas shall assist Customer by implementing appropriate technical and organizational measures, insofar as this is possible, to enable the fulfillment of Customer’s obligations, as reasonably understood by Customer, to respond to requests to exercise Data Subject rights under the Data Protection Laws.
7.4 Civitas shall:
7.4.1 notify Customer within three (3) Business Days if Civitas receives a request from a Data Subject, either directly or from a Contracted Processor, under any Data Protection Law regarding Shared Personal Data;
7.4.2 not respond to any such Data Subject request except as required by Applicable Laws to which the Civitas is subject, in which case Civitas shall to the extent permitted by Applicable Laws inform Customer of that legal requirement before responding to the request.
7.5 Customer shall:
7.5.1 promptly notify Civitas of any Data Subject requests received by Customer related to Civitas’s services provided under the MSA or the Shared Personal Data exchanged under this Addendum;
7.5.2 obtain all necessary consents from Data Subjects, in writing, to the extent consent is required by Applicable Laws in order to authorize Civitas (through the Services) to communicate with Data Subjects on behalf of Customer, including but not limited to communications made via telephone, SMS message, email, push notifications, or similar means, with or without the use of automated dialing technology; and
7.5.3 promptly notify Civitas of changes to or revocations of any Data Subject consents referred to in Section 7.5.2.
8. Security
8.1 The Parties agree to implement appropriate administrative, physical, and technical safeguards to protect Shared Personal Data from unauthorized access, acquisition, disclosure, destruction, alteration, accidental loss, misuse, or damage that are no less rigorous than applicable industry standards for information security, and shall ensure that all such safeguards, including the manner in which Shared Personal Data is created, collected, accessed, received, used, stored, processed, disposed of, and disclosed, comply with Applicable Laws, as well as the terms and conditions of this Addendum.
8.2 Civitas’s safeguards for the protection of the Shared Personal Data shall include: (i) limiting access of Shared Personal Data to persons authorized to access such data; (ii) securing business facilities, data centers, paper files, servers, backup systems, and computing equipment, including, but not limited to, all mobile devices and other equipment with information storage capability; (iii) implementing network, application, database, and platform security; (iv) securing information transmission, storage, and disposal; (v) implementing authentication and access controls within media, applications, operating systems, and equipment; (vi) conducting risk assessments, penetration testing, and vulnerability scans; (vii) implementing appropriate personnel security and integrity procedures and practices, including, but not limited to, conducting background checks consistent with applicable law; and (viii) providing appropriate privacy and information security training to employees.
9. Personal Data Breach
9.1 In the event of a Personal Data Breach, responsibility for reporting the breach to Regulatory Authorities falls to the Party suffering the breach of security leading to the Personal Data Breach, unless Applicable Laws require otherwise. Civitas shall promptly notify Customer upon Civitas becoming aware of a Personal Data Breach affecting Shared Personal Data, and at that time shall provide Customer with information to allow Customer to meet any obligations to report or inform Data Subjects of the Personal Data Breach under the Data Protection Laws. Such notification shall:
9.1.1 describe the nature of the Personal Data Breach, the categories and numbers of Data Subjects concerned, and the categories and numbers of Personal Data records concerned;
9.1.2 communicate the name and contact details of Civitas’s data protection officer or other relevant contact from whom more information may be obtained;
9.1.3 describe the likely consequences of the Personal Data Breach; and
9.1.4 describe the measures taken or proposed to be taken to address the Personal Data Breach, provided that, (without prejudice to the above obligations) if Civitas cannot provide all these details within the timeframes set out in this Section, it shall (before the end of such timeframes) provide Customer with the reasons for the delay, and when it expects to be able to provide the relevant details (which may be provided in phases), and give Customer regular updates on these matters.
9.2 Customer shall promptly notify Civitas upon Customer becoming aware of a Personal Data Breach affecting or resulting in actual or suspected compromise of Civitas’s information technology assets, resources, services, or systems.The Parties agree to provide reasonable assistance as is necessary to each other to facilitate the handling of any Personal Data Breach in an expeditious and compliant manner.
10. Data Protection Cooperation
10.1 The Parties agree to provide one another with reasonable cooperation and assistance as requested by either Party in relation to any compliance measure which the Parties reasonably consider to be required by Data Protection Laws in relation to the Processing of the Shared Personal Data.
10.2 A Party may provide notice to the other Party of any variations to this Addendum which a Party reasonably considers to be necessary to address the requirements of any Data Protection Law.
10.3 If a Party gives notice under the foregoing Section, the Parties shall promptly discuss the proposed variations and negotiate in good faith with a view to agreeing and implementing those or alternative variations designed to address the requirements identified in the proposing Party’s notice as soon as is reasonably practicable.
11. Indemnification
11.1 Any breach of the Data Protection Laws, or of either Parties’ obligations under this Addendum, shall be governed by the MSA.
12. Warranties
12.1 Each Party warrants and undertakes to the other Party that:
12.1.1 it has the right, power and authority to enter into this Addendum and to perform its obligations under this Addendum;
12.1.2 to its knowledge there are no threatened or pending or actual court or regulatory actions, suits, or proceedings against or affecting that Party that might affect the ability of that Party to meet and carry out its obligations under this Addendum;
12.1.3 it is able to perform all of its obligations under this Addendum; and
12.1.4 entering this Addendum will not cause that Party to be in breach of any other contract to which it is a Party or to be in breach of any statutory or other legal requirement.
13. General Terms Governing law and jurisdiction
13.1 The Parties to this Addendum hereby submit to the choice of jurisdiction stipulated in the MSA with respect to any disputes or claims howsoever arising under this Addendum, including disputes regarding its existence, validity or termination or the consequences of its nullity.This Addendum and all non-contractual or other obligations arising out of or in connection with it are governed by the laws of the country or territory stipulated for this purpose in the MSA.
Order of precedence
13.2 In the event of inconsistencies between the provisions of this Addendum and any other agreements between the Parties, including the MSA and including (except where explicitly agreed otherwise in writing signed on behalf of the Parties) agreements entered into or purported to be entered into after the date last signed by the Parties, the provisions of this Addendum shall prevail.
Severance
13.3 Should any provision of this Addendum be invalid or unenforceable, then the remainder of this Addendum shall remain valid and in force. The invalid or unenforceable provision shall be either (i) amended as necessary to ensure its validity and enforceability, while preserving the Parties’ intentions as closely as possible or, if this is not possible, (ii) construed in a manner as if the invalid or unenforceable part had never been contained therein. By entering into an Order Form, Customer agrees that this Addendum is entered into and becomes a binding part of the MSA as of the MSA Effective Date, thereafter terminating upon the cessation of Processing under this Addendum.
Bring your questions. Leave with an estimate you can defend.
A 45-minute working session: we start from your public IPEDS figures, show what the platform found at institutions like yours, and size the outcome — before anyone touches your data.