Last Updated: 1 October 2026
Download a word version here.
This Data Processing Agreement (“DPA”) is made and entered into as of the date of last signature below (“Effective Date”) by and between you, our Customer (hereinafter referred to as “Customer”, or “Controller”), and the Cloud4Wi entity that has entered into the Agreement with you, as determined under the “Cloud4Wi Contracting Entity, Notices, Governing Law, and Venue” section of the Agreement (referred to as “Cloud4Wi” or “Processor”).
This Data Processing Agreement is a supplement to and made a part of the Customer Terms of Service (“Agreement”).
If you are accepting this Data Processing Agreement on behalf of Customer, you warrant that: (a) you have full legal authority to bind Customer to this Data Processing Agreement; (b) you have read and understand this Data Processing Agreement; and (c) you agree, on behalf of Customer, to this Data Processing Agreement. If you do not have the legal authority to bind Customer, please do not accept these Data Processing Terms.
1. DEFINITIONS
All capitalized terms used in this DPA shall have the meanings given to them below:
“Applicable Data Protection Law”: means all applicable international, federal, national and state privacy and data protection laws that apply to the processing of Personal Data that is the subject matter of the DPA (including, where applicable, European Data Protection Law).
“Cloud4Wi Group”: means Cloud4Wi, Inc. and its subsidiaries from time to time.
“Controller”: means the entity that determines the purposes and means of the processing of Personal Data, and for the purposes of this DPA means Customer.
“Customer” means in the case of an individual accepting this Agreement on his or her own behalf, such individual, or in the case of an individual accepting the Master Service Agreement on behalf of a company or other legal entity, the company or other legal entity for which such individual is accepting this Agreement, and Affiliates of that company or entity (for so long as they remain Affiliates) which have entered into Order Forms with the intention of making use of Cloud4Wi Services at one or more of its venues.
“Data Subject”: means the identified or identifiable person to whom Personal Data related.
“Documentation” means the applicable documentation at https://support.cloud4wi.ai which includes Cloud4Wi’s Policies and Agreements, as updated from time to time.
“European Data Protection Law”: means: (i) prior to 25 May 2018, the EU Data Protection Directive 95/46/EC, and any applicable national implementation of it; and (ii) on and after 25 May 2018, the EU General Data Protection Regulation 2016/679 (“GDPR”) and any applicable national laws made under the GDPR.
“Personal Data” (“Data”): means any information relating to an identified or identifiable natural person; an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
“Processor”: means an entity that processes Personal Data on behalf of the Controller, and for the purposes of this DPA means the Cloud4Wi contracting entity identified in the preamble. The identity of that entity, and the resulting processing chain, are set out in Annex 3.
“Service” (“Services”): means any product or service provided by the Processor to the Customer pursuant to the DPA and the Agreement.
The definitions not present have the same meaning as in the General Data Protection Regulation of 2016/679.
2. GENERAL DATA PROTECTION OBLIGATIONS
2.1 Relationship of the Parties: As between the Parties, Customer is the Controller and appoints Cloud4Wi as a Processor to process the Personal Data described in Annex 1.
2.2 Purpose limitation: Processor shall process the Data as a Processor only for the purposes described in Annex 1 and strictly in accordance with the documented instructions of the Customer (the “Permitted Purpose”) and processing outside the scope of these instructions (if any) shall require prior written agreement between Customer and Cloud4Wi; Cloud4Wi shall inform the customer if in its opinion the instructions given are breaching Applicable Data Protection Laws.
Notwithstanding anything to the contrary in the Agreement (including this DPA), Cloud4Wi may process the following data as a controller in its own right, for the purposes stated and on the basis of its legitimate interests under Article 6(1)(f) GDPR or, where applicable, the performance of the Agreement under Article 6(1)(b) GDPR:
- Account Data, meaning the business contact details of Customer’s administrators and billing contacts, for the purposes of contract administration, billing, account management, the provision of technical support, and communications concerning the Services;
- Service Telemetry, meaning technical and statistical data concerning the configuration, availability, performance and volume of use of the Services, such as counts of features used, numbers of concurrent connections, request volumes and error rates, for the purposes of securing, operating, troubleshooting, capacity planning, scaling and improving the Services.
Service Telemetry is processed in aggregated form and is not used to identify or profile any Data Subject. No Cloud4Wi Group entity uses Personal Data relating to Customer’s end users for its own marketing purposes, or discloses it to any third party for that purpose. All other processing of Personal Data under this DPA is carried out by Cloud4Wi as a Processor on Customer’s documented instructions. Information on the processing of Account Data and Service Telemetry is provided in the Cloud4Wi Privacy Information at https://support.cloud4wi.ai/hc/en-us/articles/360044124892-Privacy-Information.
2.3 International transfers of Data: Cloud4Wi shall at all times provide an adequate level of protection for the Data wherever it is processed, in accordance with Applicable Data Protection Law.
Where the provision of the Services involves a transfer of Data from the European Economic Area, the United Kingdom or Switzerland to a country that has not been the subject of an adequacy decision, that transfer is made on the basis of the Standard Contractual Clauses incorporated at Annex 3, completed as set out in that Annex, together with the supplementary measures described there.
Customer acknowledges that Cloud4Wi, Inc. is established in the United States and that personnel of Cloud4Wi, Inc. and of other Cloud4Wi Group entities may access Data for the purposes of providing, supporting and securing the Services, including where the Data is hosted in the European Economic Area. Such access constitutes a transfer for the purposes of Chapter V of the GDPR and is covered by Annex 3.
Cloud4Wi maintains a documented assessment of the laws and practices of each destination country relevant to the transfers described in Annex 3, and of the supplementary measures applied. Cloud4Wi will make that assessment available to Customer on reasonable request and will review it at least annually and on any material change.
2.4 Confidentiality of processing: The Processor shall keep strictly confidential all Personal Data that it processes on behalf of Customer. The Processor shall ensure that any person that it authorises to process the Data (including the Processor’s staff, agents and subcontractors) (each an “Authorised Person”) shall be subject to a strict duty of confidentiality (whether a contractual duty or a statutory duty), and shall not permit any person to process the Data who is not under such a duty of confidentiality. Processor shall ensure that only Authorised Persons will have access to, and process, the Data, and that such access and processing shall be limited to the extent strictly necessary to achieve the Permitted Purpose. Processor accepts responsibility for any breach of this DPA caused by the act, error or omission of an Authorised Person.
2.5 Security: Processor shall implement appropriate technical and organisational measures to protect the Data from (i) accidental or unlawful destruction, and (ii) loss, unauthorized alteration, unauthorised disclosure of, or unauthorized access to the Data. At a minimum, such measures shall include the security measures identified in Annex 2 to this DPA.
Customer acknowledges that the Service is not intended or designed for the Processing of Sensitive Information, and the Customer agrees not to provide any Sensitive Information through the Service.
2.6 Subcontracting: Customer provides a general written authorisation for Cloud4Wi to engage sub-processors to process the Data, subject to the following conditions.
- Cloud4Wi maintains an up-to-date list of its sub-processors, published at https://support.cloud4wi.ai/hc/en-us/articles/360003452492-Sub-processors-and-infrastructure and available to Customer on request, stating for each the categories of Data processed, the nature of the processing and the location of processing.
- Cloud4Wi gives Customer at least thirty (30) days’ prior notice of the intended addition or replacement of a sub-processor. Customer may subscribe to notifications of changes to the list by following that page.
- Customer may object to an intended addition or replacement on reasonable data protection grounds within thirty (30) days of that notice. Where Customer objects, the parties shall discuss in good faith whether the concern can be addressed, for example by a change in configuration or in the location of processing. If it cannot be addressed within a reasonable period, Customer may terminate the affected Services by written notice, and Cloud4Wi shall refund any prepaid fees covering the remainder of the terminated subscription term.
- Cloud4Wi shall impose on each sub-processor data protection obligations that are in substance no less protective than those in this DPA, and shall remain fully liable to Customer for the performance of each sub-processor’s obligations.
- Customer acknowledges that the Cloud4Wi Group entity that is not the contracting entity acts as a sub-processor in respect of the Services, as described in Annex 3, and is authorised on that basis.
Cloud4Wi may engage the sub-processors listed at https://support.cloud4wi.ai/hc/en-us/articles/360003452492-Sub-processors-and-infrastructure, including sub-processors located outside the European Economic Area, subject to the conditions in this section and to the transfer mechanisms set out in Annex 3.
2.7 Cooperation and individuals’ rights: To the extent permitted by Applicable Law, Processor shall provide reasonable and timely assistance to Customer to enable Customer to respond to: (i) any request from an individual to exercise any of its rights under Applicable Data Protection Law; and (ii) any other correspondence, enquiry or complaint received from an individual, regulator, court or other third party in connection with the processing of the Data. In the event that any such communication is made directly to Processor, Processor shall instruct such individual to contact Customer directly.
2.8 Data Protection Impact Assessment: If Processor believes or becomes aware that its processing of the Data is likely to result in a high risk to the data protection rights and freedoms of individuals, it shall promptly inform Customer of the same. Processor shall provide Customer with all such reasonable and timely assistance as Customer may require in order to conduct a data protection impact assessment and, if necessary, consult with its relevant data protection authority.
2.9 Security incidents: Upon becoming aware of a Security Incident, Processor shall inform Customer without undue delay (and, in any event, within 32 hours) and shall provide such timely information and cooperation as Customer may require in order for Customer to fulfil its data breach reporting obligations under (and in accordance with the timeliness required by) Applicable Data Protection Law and relevant contractual obligations owed by Customer to its subscribers. Processor shall cooperate with Customer in taking all appropriate measures and actions as are necessary to remedy or mitigate the effects of the Security Incident, shall manage and modify its systems to remedy or mitigate such Security Incident and the likelihood of future similar Security Incidents, and shall keep Customer informed of all developments in connection with the Security Incident. Processor shall not notify any third parties of a Security Incident affecting the Data unless and to the extent that: (a) Customer has agreed to such notification, and/or (b) notification is required to be made by Processor under Applicable Data Protection Laws.
2.10 Deletion or return of Data: Upon termination or expiry of the DPA, Processor shall (at Customer’s request) destroy all Data (including all copies of the Data) in its possession or control (including any Data subcontracted to a third party for processing); provided, however, that customer data (including Data) may be retained on backup for a period of up to eighteen (18) months for legal and compliance purposes. Notwithstanding the foregoing, Processor shall not reduce the security measures at any time until such Data is permanently deleted.
2.11 Audit: Processor shall permit Customer (or its appointed third-party auditors) to audit Processor’s compliance with this DPA, and shall make available to Customer all information, systems and staff necessary for Customer (or its third-party auditors) to conduct such audit. Processor acknowledges that Customer (or its third-party auditors) may enter its premises for the purposes of conducting this audit, provided that Customer gives it reasonable prior notice of its intention to audit, conducts its audit during normal business hours, and takes all reasonable measures to prevent unnecessary disruption to Processor’s operations. Customer will not exercise its audit rights more than once in any twelve (12) calendar month period, except (i) if and when required by instruction of a competent data protection authority; or (ii) Customer believes a further audit is necessary due to a Security Incident suffered by Processor. Processor shall also respond to any written audit questions submitted to it by Customer.
2.12 Indemnity: Processor (the “Indemnifying Party”) shall defend and fully indemnify Customer from and against all loss, harm, cost (including reasonable attorney’s fees), fines, expense, and liability that Customer may suffer or incur arising as a result of Processor’s breach or non-compliance with this DPA. The foregoing shall be subject to the indemnification procedures set forth in the Agreement.
2.13 General cooperation to remediate: In the event that Applicable Data Protection Law, or a data protection authority or regulator, provides that the transfer or processing of Personal Data under this DPA is no longer lawful or otherwise permitted, then the Parties shall agree to remediate the processing (by amendment to this DPA or otherwise) to the extent practical in order to meet the necessary standards or requirements. If Processor is unable to remediate the processing, then Customer will be entitled to terminate the DPA (and any other agreement between the Parties relating to the provision of services by Processor to Customer) without penalty.
2.14 System administrators: If mandatory under applicable data protection laws, the Processor will appoint System Administrators responsible for managing the systems used to process Controller’s personal data.
3. TERM
3.1 The obligations placed upon the Processor under this DPA shall survive so long as Processor and/or its sub-Processors Process Personal Data on behalf of Customer.
ANNEX 1 – DETAILS OF PROCESSING OF CONTROLLER PERSONAL DATA
This Annex 1 includes certain details of the Processing of Controller Personal Data as required by Article 28(3) GDPR.
Subject matter and duration of the Processing of Controller Personal Data
The subject matter and duration of the Processing of the Controller Personal Data are set out in the Agreement and this DPA.
The nature and purpose of the Processing of Controller Personal Data
Cloud4Wi will Process Personal Data as necessary to perform the Services pursuant to the Agreement, as further specified in the Service Documentation, and as further instructed by Customer in its use of the Services.
The processing of the categories of personal data listed below is at the sole discretion of the Controller depending on how the Service is configured.
The categories of Data Subject to whom the Controller Personal Data relates
The Customer may collect Personal Data with the Service, the extent of which is determined and controlled by Customer, and which may include, but is not limited to, Personal Data relating to the following categories of data subjects:
- Prospects, customers, visitors, subscribers of the Customer (who are natural persons)
- Residents and occupants of multi-dwelling properties, and visitors and contractors at the Customer’s premises
- Employees, agents, advisors or business partners of the Customer
- Customer’s users authorized by the Customer to use the Service
The types of Personal Data to be Processed
The Customer may collect and submit Personal Data of Users and Subscribers to the Processor, the extent of which is determined and controlled by Customer in its sole discretion, depending also on services, products, licenses, and subscriptions purchased by the Customer, and which may include, but is not limited to, the following categories of Personal Data:
- Identification and contact data: name, email address, phone number, identifiers from social login or other services, and any further fields the Customer adds to its registration forms or surveys
- Authentication data: login method and credentials (passwords stored hashed), one-time codes, corporate identities and group memberships validated against the Customer’s identity provider, Passpoint and OpenRoaming profile identifiers, and authentication records
- Device data: device identifiers including the MAC address, device model and operating system
- Network usage data: connection logs, including start and end time, duration, access point and venue, data volume and IP address
- Location data at venue level: history of visited venues and access points, visit frequency and dwell time
- Marketing and preference data: opt-ins, consents and preferences collected by the Customer, and data used to run the Customer’s email and SMS campaigns
- Analytics and segmentation data: reports and segments the Customer configures on its end users
The Customer may also submit content to Service which may include other Personal Data and special categories of data, the extent of which is determined and controlled by the Customer in its sole discretion.
ANNEX 2 – DESCRIPTION OF THE TECHNICAL AND ORGANIZATIONAL SECURITY MEASURES
This Annex 2 includes the description of the technical and organizational security measures implemented by the Data Processor.
Cloud4Wi currently observes the security practices described in this Annex 2. Notwithstanding any provision to the contrary otherwise agreed to by data exporter, Cloud4Wi may modify or update these practices at its discretion provided that such modification and update does not result in a material degradation in the protection offered by these practices. All capitalized terms not otherwise defined herein shall have the meanings as set forth in this DPA.
a) Access Control
i) Preventing Unauthorized Product Access
Outsourced processing: Cloud4Wi hosts its Service with outsourced cloud infrastructure providers. Additionally, Cloud4Wi maintains contractual relationships with vendors in order to provide the Service in accordance with this DPA. Cloud4Wi relies on contractual agreements, privacy policies, and vendor compliance programs in order to protect data processed or stored by these vendors.
Physical and environmental security: Cloud4Wi hosts its product infrastructure with multi-tenant, outsourced infrastructure providers. The physical and environmental security controls are audited for SOC 2 Type II and ISO 27001 compliance, among other certifications.
Authentication: Cloud4Wi implemented a uniform password policy for its customer products. Customers who interact with the products via the user interface must authenticate before accessing non-public customer data.
Authorization: Customer data is stored in multi-tenant storage systems accessible to Customers via only application user interfaces and application programming interfaces. Customers are not allowed direct access to the underlying application infrastructure. The authorization model in each of Cloud4Wi’s products is designed to ensure that only the appropriately assigned individuals can access relevant features, views, and customization options. Authorization to data sets is performed through validating the user’s permissions against the attributes associated with each data set.
Application Programming Interface (API) access: Public product APIs may be accessed using an API key.
ii) Preventing Unauthorized Product Use
Cloud4Wi implements industry standard access controls and detection capabilities for the internal networks that support its products.
Access controls: Network access control mechanisms are designed to prevent network traffic using unauthorized protocols from reaching the product infrastructure. The technical measures implemented differ between infrastructure providers and include Virtual Private Cloud (VPC) implementations, security group assignment, and traditional firewall rules.
Intrusion detection and prevention: Cloud4Wi implemented a Web Application Firewall (WAF) solution to protect hosted customer websites and other internet-accessible applications. The WAF is designed to identify and prevent attacks against publicly available network services.
Static code analysis: Security reviews of code stored in Cloud4Wi’s source code repositories are performed, checking for coding best practices and identifiable software flaws.
Penetration testing: Cloud4Wi maintains relationships with industry recognized penetration testing service providers for four annual penetration tests. The intent of the penetration tests is to identify and resolve foreseeable attack vectors and potential abuse scenarios.
iii) Limitations of Privilege & Authorization Requirements
Product access: A subset of Cloud4Wi’s employees have access to the products and to customer data via controlled interfaces. The intent of providing access to a subset of employees is to provide effective customer support, to troubleshoot potential problems, to detect and respond to security incidents and implement data security. Access is through a default support role that masks end-user personal data and blocks the export of users and other actions affecting personal data; administrator access is used only at the Customer’s request through the official support channels. Customers established in the European Economic Area are supported by personnel in the EEA, with access from outside the EEA only on escalation of a support request. Employees are granted access by role, and reviews of high risk privilege grants are performed periodically. Employee roles are reviewed at least once every six months.
Background checks: All Cloud4Wi employees undergo a background check prior to being extended an employment offer, in accordance with the applicable laws. All employees are required to conduct themselves in a manner consistent with company guidelines, non-disclosure requirements, and ethical standards.
b) Transmission Control
In-transit: Cloud4Wi makes HTTPS encryption (also referred to as SSL or TLS) available on every one of its login interfaces and for every Splash Page hosted on the Cloud4Wi products. Cloud4Wi HTTPS implementation uses industry standard algorithms and certificates.
At-rest: Cloud4Wi stores user passwords following policies that follow industry standard practices for security. With effect 25 May 2018, Cloud4Wi has implemented technologies to ensure that stored data is encrypted at rest.
c) Input Control
Detection: Cloud4Wi designed its infrastructure to log extensive information about the system behavior, traffic received, system authentication, and other application requests. Internal systems aggregated log data and alert appropriate employees of malicious, unintended, or anomalous activities. Cloud4Wi personnel, including security, operations, and support personnel, are responsive to known incidents.
Response and tracking: Cloud4Wi maintains a record of known security incidents that includes description, dates and times of relevant activities, and incident disposition. Suspected and confirmed security incidents are investigated by security, operations, or support personnel; and appropriate resolution steps are identified and documented. For any confirmed incidents, Cloud4Wi will take appropriate steps to minimize product and Customer damage or unauthorized disclosure.
Communication: If Cloud4Wi becomes aware of unlawful access to Customer data stored within its products, Cloud4Wi will: 1) notify the affected Customers of the incident; 2) provide a description of the steps Cloud4Wi is taking to resolve the incident; and 3) provide status updates to the Customer contact, as Cloud4Wi deems necessary. Notification(s) of incidents, if any, will be delivered to one or more of the Customer’s contacts in a form Cloud4Wi selects, which may include via email or telephone.
d) Availability Control
Infrastructure availability: The infrastructure providers use commercially reasonable efforts to ensure a minimum of 99.95% uptime. The providers maintain a minimum of N+1 redundancy to power and network.
Fault tolerance: Backup and replication strategies are designed to ensure redundancy and fail-over protections during a significant processing failure. Customer data is backed up to multiple durable data stores and replicated across multiple availability zones.
Online replicas and backups: Where feasible, production databases are designed to replicate data between no less than 1 primary and 1 secondary database. All databases are backed up and maintained using at least industry standard methods.
Cloud4Wi’s products are designed to ensure redundancy and seamless failover. The server instances that support the products are also architected with a goal to prevent single points of failure. This design assists Cloud4Wi operations in maintaining and updating the product applications and backend while limiting downtime.
ANNEX 3 – INTERNATIONAL TRANSFERS AND PROCESSING CHAINS
1. Processing chains
The identity of the Processor, and the resulting chain, depends on the Cloud4Wi contracting entity determined under the Agreement.
Chain A — Customer contracts with Cloud4Wi, Inc.
| Controller | Customer |
| Processor | Cloud4Wi, Inc., Delaware, United States |
| Sub-processors | Cloud4Wi S.r.l., Italy, for development, maintenance and support; and the infrastructure and other sub-processors listed at https://support.cloud4wi.ai/hc/en-us/articles/360003452492-Sub-processors-and-infrastructure |
| Transfer | Where Customer is established in the EEA, the UK or Switzerland, or the Data otherwise originates there, the transfer to Cloud4Wi, Inc. is a restricted transfer and is made on the basis of the Module Two Clauses at section 2 below |
Chain B — Customer contracts with Cloud4Wi S.r.l.
| Controller | Customer |
| Processor | Cloud4Wi S.r.l., Italy |
| Sub-processors | Cloud4Wi, Inc., United States; and the infrastructure and other sub-processors listed at https://support.cloud4wi.ai/hc/en-us/articles/360003452492-Sub-processors-and-infrastructure |
| Transfer | No restricted transfer arises between Customer and Cloud4Wi S.r.l. The onward transfer from Cloud4Wi S.r.l. to Cloud4Wi, Inc. is a restricted transfer and is made on the basis of the Module Three Clauses, concluded between those entities under the intra-group data protection agreement |
2. Standard Contractual Clauses
The Standard Contractual Clauses approved by Commission Implementing Decision (EU) 2021/914 of 4 June 2021 are incorporated into this DPA by reference and form part of it, with Module Two (controller to processor) applying to Chain A, completed as follows.
- Clause 7, the docking clause, applies.
- In Clause 9, Option 2, general written authorisation, applies, with a notice period of thirty days as provided in §2.6 of this DPA.
- In Clause 11, the optional independent dispute resolution paragraph does not apply.
- In Clause 17, the Clauses are governed by the law of Ireland.
- In Clause 18(b), disputes are to be resolved before the courts of Ireland.
- Annexes I, II and III to the Clauses are completed as set out in sections 3 to 5 below.
Where Customer is established in, or the Data originates in, the United Kingdom, the International Data Transfer Addendum issued by the Information Commissioner under section 119A of the Data Protection Act 2018 applies to the Clauses. Where Customer is established in, or the Data originates in, Switzerland, the Clauses apply with the adaptations required by the Swiss Federal Act on Data Protection, including references to the Federal Data Protection and Information Commissioner as competent authority.
In the event of a conflict between the Clauses and the remainder of this DPA, the Clauses prevail.
3. Annex I to the Clauses
A. List of parties
Data exporter. Customer, as identified in the Order Form, acting as controller in respect of the Data described below. Contact details, and the name and contact details of Customer’s data protection officer or representative where one has been appointed, are those provided by Customer in the Order Form or in the Services. Activities relevant to the transfer: receipt of the Services described in the Order Form. Signature and date: as provided in MSA §2.2. Role: controller.
Data importer. Cloud4Wi, Inc., 77 Sands Street, NY 11201, United States of America. Contact: privacy@cloud4wi.com. Activities relevant to the transfer: provision, support, maintenance and security of the Services. Signature and date: as provided in MSA §2.2. Role: processor.
B. Description of transfer
Categories of data subjects. As set out in Annex 1 to this DPA.
Categories of personal data. As set out in Annex 1 to this DPA.
Sensitive data. The Services are not intended or designed for the processing of special categories of data, and Customer agrees not to submit such data through the Services.
Frequency of the transfer. Continuous, for the duration of the Agreement.
Nature of the processing. Collection, recording, organisation, structuring, storage, retrieval, consultation, use, disclosure by transmission, restriction, erasure and destruction, as necessary to provide the Services.
Purpose of the processing. Provision of the Services under the Agreement and the applicable Order Form, in accordance with Customer’s documented instructions.
Retention. For the duration of the Agreement and thereafter as provided in §2.10 of this DPA.
Sub-processors. As listed at https://support.cloud4wi.ai/hc/en-us/articles/360003452492-Sub-processors-and-infrastructure, for the duration of their engagement and for the processing described in that list.
C. Competent supervisory authority
The supervisory authority of the Member State in which the data exporter is established. Where the data exporter is not established in the European Economic Area but is subject to the GDPR under Article 3(2), the supervisory authority of the Member State in which the data exporter’s Article 27 representative is established.
4. Annex II to the Clauses — technical and organisational measures
The technical and organisational measures are those set out in Annex 2 to this DPA, which are incorporated into the Clauses as Annex II.
5. Annex III to the Clauses — list of sub-processors
The sub-processors authorised by Customer are those listed at https://support.cloud4wi.ai/hc/en-us/articles/360003452492-Sub-processors-and-infrastructure, as updated in accordance with §2.6 of this DPA, together with Cloud4Wi S.r.l. in Chain A and Cloud4Wi, Inc. in Chain B.
6. Supplementary measures
Cloud4Wi applies the following measures in support of the Clauses, in addition to those in Annex 2:
- hosting of Customer Data within the European Economic Area, in Ireland, except for the application layer of the Cusna multi-tenant solution, which is hosted in the United States as stated in the sub-processor list;
- encryption of Data in transit and at rest, with keys managed under the Encryption and Key Management Policy;
- access by personnel of the data importer and of Group sub-processors on a need-to-know basis, through a default support role that masks end-user personal data and blocks the export of users; administrator access only at the Customer’s request through the official support channels; and support of Customers established in the EEA by personnel in the EEA, with access from outside the EEA only on escalation of a support request (EEA Support Access Policy);
- a policy of challenging any request for disclosure received from a public authority where there are lawful grounds to do so, of seeking interim measures to suspend the effect of the request pending judicial determination, and of providing only the minimum amount of data permitted under a reasonable interpretation of the request;
- notification to Customer of any legally binding request for disclosure of the Data by a public authority, unless prohibited by law, and in that case of the fact that such requests may have been received, by means of a periodic transparency report;
- maintenance of a documented transfer impact assessment as provided in §2.3, reviewed at least annually.