Paradraw
1Password/1Password Partner Agreement | 1Password is drafted as if it could incorporate Data Processing Agreement | SaaS Manager | 1Password
1Password Partner Agreement | 1Password · Clause 1.14.2
perimeter

1Password Partner Agreement | 1Password

8,345 words, 138 clausesupdated January 13, 2026read 08/10/2026source

·1Password Partner Program Agreement

·Last updated: January 13, 2026

·BY SUBMITTING AN APPLICATION TO JOIN THE 1PASSWORD PARTNER PROGRAM, PARTICIPATING IN THE 1PASSWORD PARTNER PROGRAM, PLACING AN ORDER FOR THE SERVICES, OR CLICKING "I AGREE" OR A SIMILAR PHRASE WHEN YOU SIGN UP FOR A PARTNER ACCOUNT, YOU AGREE TO BE BOUND BY THE APPLICABLE SECTIONS OF THE FOLLOWING PARTNER PROGRAM AGREEMENT (THE "PARTNER AGREEMENT").

·THE PARTNER AGREEMENT IS BETWEEN YOU, AS PARTNER (AS DEFINED BELOW IN SECTION A.1.), AND AGILEBITS INC. (DBA 1PASSWORD), A CORPORATION INCORPORATED UNDER THE LAWS OF THE PROVINCE OF ONTARIO, CANADA, AND HAVING ITS PRINCIPAL PLACE OF BUSINESS AT 4711 YONGE ST, 10TH FLOOR, TORONTO, ONTARIO, M2N 6K8, CANADA ("1PASSWORD"). EACH OF PARTNER AND 1PASSWORD IS A "PARTY" AND TOGETHER THE "PARTIES".

·YOU CAN REVIEW THE CURRENT VERSION OF THE PARTNER AGREEMENT AT ANY TIME AT HTTPS://1PASSWORD.COM/LEGAL/PARTNERSHIP-AGREEMENT. IF A SIGNIFICANT CHANGE IS MADE, 1PASSWORD WILL PROVIDE REASONABLE NOTICE EITHER BY EMAIL, OR IN YOUR PARTNER DASHBOARD. YOU ARE ADVISED TO CHECK THE PARTNER AGREEMENT FROM TIME TO TIME FOR ANY UPDATES OR CHANGES THAT MAY IMPACT YOU. ANY REFERENCE TO THE PARTNER AGREEMENT INCLUDES ANY AND ALL TERMS AND DOCUMENTS INCORPORATED BY REFERENCE.

·YOU REPRESENT THAT YOU PARTNER HAS GIVEN YOU FULL AUTHORITY TO BIND THE PARTNER TO THE PARTNER AGREEMENT. IF YOU DO NOT HAVE THIS AUTHORITY, OR YOU OR PARTNER DO NOT AGREE TO, OR CANNOT COMPLY WITH, THE PARTNER AGREEMENT, THEN YOU OR PARTNER MAY NOT SUBMIT AN APPLICATION, PARTICIPATE IN THE 1PASSWORD PARTNER PROGRAM, REQUEST A QUOTE OR PLACE AN ORDER WITH 1PASSWORD.

·THIS PARTNER AGREEMENT ADDRESSES DIFFERENT TYPES OF PARTNER ACTIVITIES: PART A APPLIES TO ALL PARTNERS; PART B APPLIES TO RESELLERS; PART C MANAGED SERVICE PROVIDERS. IF YOU DO NOT PARTICIPATE IN PARTNER ACTIVITIES DESCRIBED IN PARTS B, OR C, THEN THESE PARTS OF THE PARTNER AGREEMENT DO NOT APPLY TO YOU.

Part APART A - APPLIES TO ALL PARTNERS

11. Definitions

·Unless defined elsewhere in the Partner Agreement, capitalized terms set out in the Partner Agreement are defined as follows:

1.11.1 "1Password Terms" refers to the terms and conditions governing Customer's access to and use of the Services, as detailed at https://1password.com/legal/terms-of-service. This includes, where applicable, the Data Processing Agreement and any related policies, all of which may be updated, amended, or revised from time to time by 1Password at its sole discretion. These Terms of Service outline the rights, responsibilities, and obligations of both 1Password and the Customer in relation to the Services.

1.21.2 "Affiliate" means any majority-owned subsidiary or other entity which a party controls or is controlled by, or with which it is under common control with a party.

1.31.3 "Authorized Users"means those individuals associated with a Customer and who have been authorized by the Customer to access and use the Services.

1.41.4 "Brand Guidelines"means the 1Password brand guidelines available at: https://brand.1password.com/document/45#/-/download-our-all-in-one-press-kit

1.51.5 "Confidential Information" has the meaning given to that term in Section 13.1.

1.61.6 "Customer" means any legal entity with which the Partner has entered into a commercial relationship for the use of the Services. Customers are bound by either: (i) the 1Password Terms; or (ii) a negotiated agreement between the Customer and 1Password.

1.71.7 "Documentation" means any materials, resources, guides, manuals, specifications, or related content made available by 1Password to the Partner. This documentation is intended to provide detailed information, guidance, or instructions regarding the use, integration, promotion, or support of the Services or Partner Program.

1.81.8 "Effective Date" means the date that the Partner accepts this Partner Agreement.

1.91.9 "Intellectual Property" means any and all tangible and intangible rights associated with and now known or hereafter existing: (i) works of authorship throughout the universe including, but not limited to, copyrights, moral rights, and mask works; (ii) trademarks, service marks and trade name rights and similar rights; (iii) trade secrets; (iv) patents, designs, algorithms and other industrial property rights; (v) all other intellectual and industrial property and proprietary rights of every kind and nature throughout the universe and however designated, whether arising by operation of law, contract, license or otherwise; and (vii) all registrations, applications, renewals, extensions, continuations, divisions or reissues thereof now or hereafter in force globally.

1.101.10 "International Trade Control Authority" means (i) the United States, (ii) Canada, (iii) the United Nations Security Council, (iv) the European Union, (v) any Member State of the EU, (vi) the United Kingdom, (vii) the respective governmental institutions of any of the foregoing including, without limitation, or (viii) any other relevant authority.

1.111.11 "International Trade Control Laws" means laws and regulations governing the export, re-export, transfer, or re-transfer of goods, software, technology, technical data, and technical services, and economic or financial sanctions (such as restrictive measures, asset freezes, etc.) or trade embargoes, decisions, executive orders, notices, or other comprehensive or non-comprehensive prohibitions against transaction activity, imposed, implemented, enacted, administered, or enforced by any International Trade Control Authority.

1.121.12 "Managed Customers" means those Customers purchasing the Managed Service Services through the MSP pursuant to an agreement with the MSP.

1.131.13 "Managed Identity" means non-service account identities listed with an 'active' status in the Customer's primary identity provider (IdP), as integrated with the Services."

1.141.14 "Managed Services" means MSP's managed service offering in which MSP provides a Managed Customer with access to the Services along with implementation, billing and support services.

1.151.15 "MSP Data" means any information, data, or content provided or uploaded by the MSP, a Managed Customer or its Authorized Users within the Services.

1.161.16 "Partner"means an entity that has agreed to the terms of this Partner Agreement and participates in the 1Password Partner Program. The different types of Partners are listed below and Partner may qualify as more than one type of Partner concurrently for the purpose of this Partner Agreement, depending on the circumstances:

  • 1.16.11.16.1 "Reseller" is a Partner authorized to market, promote, and sell the 1Password Services to Customers. The Reseller acts as an intermediary between 1Password and Customers and facilitates sales without altering the 1Password's Services.
  • 1.16.21.16.2 "Managed Service Provider" or "MSP" means Partners that sell and provide Managed Services to Managed Customers.

1.171.17 "Partner Program" means the resources made available by 1Password to Partners from time to time.

1.181.18 "Purchase Order" shall mean a purchase order document, in tangible or intangible form (e.g. .rtf, .pdf, formats, etc.), issued by Partner, indicating acceptance of the referenced Quotation, without regards to any conflicting terms and conditions presented therein, except with respect to price, quantity, and location.

1.191.19 "Order Form" means a document that outlines the specific terms and conditions for the purchase of Services by Partner on behalf of Customer, including but not limited to descriptions, quantities, pricing, payment terms, and other relevant details.

1.201.20 "Quotation" means a written quotation issued by 1Password to the Partner for certain Services required by the Partner for resale to the Customers.

1.211.21 "Resale License" means the rights, licenses and subscriptions granted by 1Password to Partner pursuant to Section 3 of this Partner Agreement.

1.221.22 "Restricted Party" means a person, whether or not having a legal personality, (or persons in aggregate) who (a) is (or are) listed on any Sanctions List, (b) or is (or are) "owned" directly or indirectly, individually or in the aggregate, 50% or greater, or "controlled" (as such terms are defined and construed in International Trade Control Laws in any related official guidance), directly or indirectly, by a person (or persons in aggregate) who is (or are) listed on any Sanctions List, or (c) is or has been acting on behalf or at the direction of a person (or persons in aggregate) who is identified in (a) or (b) above or is otherwise targeted by International Trade Control Laws.

1.231.23 "Sanctions List" means all sanctions lists maintained by any of the competent International Trade Control Authorities as amended, supplemented, or substituted, including but not limited to the U.S. Department of the Treasury's Office of Foreign Assets Control's (OFAC) Specially Designated Nationals List, Sectoral Sanctions Identification List, and the Foreign Sanctions Evaders List; the U.S. Department of Commerce's Entity List, Unverified List Denied Persons List, or Military End User List; the Consolidated Canadian Autonomous Sanctions List; the Consolidated List of Financial Sanctions Targets issued by His Majesty's Treasury and the UK Sanctions List; and the EU Consolidated list of persons, groups and entities subject to EU financial sanctions and entities subject to EU financial sanctions listed in Annex XIX of Council Regulation (EU) No 833/2014.

1.241.24 "Services" means 1Password's subscription service(s), including any and all related or underlying technology, code, know-how, logos, and templates, anything delivered as part of support or other services, and any updates, modifications or derivative works of any of the foregoing.

1.251.25"Taxes" means all federal, provincial, state, local or other governmental sales, value added, goods and services, harmonized or other taxes, fees or charges now in force or enacted in the future.

1.261.26 "Territory" means any territory established by 1Password with the Partner.

22. Purpose

2.12.1 This Partner Agreement sets forth the terms and conditions under which the 1Password authorizes Partners to promote, market, and resell the 1Password's Services. The purpose of this Partner Agreement is to establish a collaborative partnership that enables Partners to distribute the 1Password Services to Customers, either directly or through authorized channels, in a manner that benefits all parties.

33. Grant of License

3.13.1 Grant of Resale License. 1Password hereby grants to Partner a non-transferable, non-exclusive, non-exclusive license to promote, market, distribute, and resell the Services to Customers in the Territory during the term of this Partner Agreement (the "Resale License"), subject at all times to the terms and conditions of this Partner Agreement, as it may be updated and amended by 1Password from time to time in its sole discretion. 1Password acknowledges that Partner retains the right to market services on behalf of other service providers which are the same or substantially similar to the 1Password Services described herein.. Partner will have no right, power, or authority to bind or obligate 1Password in any manner whatsoever except as specifically provided herein. 1Password retains all ownership rights, title, and interest in and to the Services and any technology therein, including all intellectual property rights therein and thereto.

3.23.2 Customer Termination. Partner agrees that, for the duration of this Partner Agreement, Partner will not directly or indirectly solicit or encourage any Customer to terminate 1Password Services. However, Partners may facilitate termination of Services at the Customer's request or in accordance with the Terms.

3.33.3 Evaluation Agreements. If the applicable Purchase Order indicates that the licenses granted are for evaluation purposes, 1Password hereby grants Partner a temporary, non-exclusive, non-transferable, and revocable license to resell the Services solely for internal testing, evaluation, proof-of-concept, or demonstration purposes during the specified evaluation period.

44. Intellectual Property

4.14.1 Marks. 1Password retain all rights, title, and interest in and to our Services, including any modifications or derivative works thereof, except for those rights expressly granted to you in this Partner Agreement. Neither Party shall use or register any marks, trade names, domain names, or other identifiers (collectively, "Marks") of the other party, or any marks that are confusingly similar to those of the other Party. 1Password reserves the right to use Partner Marks solely to reference Partner as an authorized Partner. Partner may utilize 1Password Marks in relation to the Services, but only in accordance with the Brand Guidelines, along with any additional partner style guidelines we may provide through written communication. Should 1Password provide written notice that Partner's use of 1Password Marks does not comply with the Brand Guidelines, Partner will immediately cease or suspend such use in any marketing materials.

4.24.2 Partner Marks. 1Password may use Partner's name, logo, and marks ("Partner Marks") to identify Partner as a 1Password Partner on 1Password's website and other marketing materials. 1Password may identify the Partner during communications with 1Password's partners, customers, or prospects without Partner's consent. All use of Partner Marks will be in accordance with any marketing and usage guidelines provided by Partner, as they may be reasonably amended from time to time.

4.34.3 Restrictions. Partner shall not, and shall not cause, encourage or assist any third party to: (a) access or use the Services in excess of what is allowed in this Partner Agreement, or pursuant to any other limitations described in a Quote or Purchase Order; (b) alter, translate, create derivative works of or otherwise modify the Services; (c) reverse engineer, decompile, disassemble or otherwise attempt to derive the detection methodology or data, source code, algorithms, or machine learning methods for a Service (except to the extent that such prohibition is expressly precluded by applicable law), circumvent its functions, or attempt to gain unauthorized access to a Service or its related systems or networks; (d) remove or alter any notice of proprietary right appearing in the Services, or affix or place any labels or markings in the Services that might be interpreted as a claim of ownership by Partner or any third party; (e) conduct any benchmark, stress tests or other review or analysis for the purpose of competing with 1Password, or (f) perform an analysis of the Offerings versus competitor products or publish a review or the results of any evaluation of the Services unless approved by 1Password in writing.

4.44.4 Feedback. Partner may provide 1Password with suggestions, comments and feedback regarding the Services, including but not limited to usability, bug reports and test results, with respect to the foregoing (collectively, "Feedback"). Partner grants 1Password a worldwide, non-exclusive, perpetual, irrevocable, royalty free, fully paid up right without any attribution of any kind (and without publicly identifying Partner): (i) to make, use, copy, modify, sell, distribute, sub-license, and create derivative works of, the Feedback as part of any Service or related technology, specification or other documentation; (ii) to publicly perform or display, import, broadcast, transmit, distribute, license, offer to sell, and sell, rent, lease or lend copies of the Feedback (and derivative works thereof) as part of any Service or related technology, specification or other documentation; (iii) solely with respect to Partner's copyright and trade secret rights, to sublicense to third parties the foregoing rights, including the right to sublicense to further third parties; and (iv) to sublicense to third parties any claims of any patents owned or licensable by Partner that are necessarily infringed by a third party product, technology or service that uses, interfaces, interoperates or communicates with the Feedback or portion thereof incorporated into an Offering or related technology, specification or other documentation. Further, Partner warrants that its Feedback is not subject to any license terms that would purport to require 1Password to comply with any additional obligations with respect to any Service or related technology, specification or other documentation that incorporate any Feedback.

55. Partner Responsibilities

5.15.1 1Password Terms. The Partner is responsible for ensuring that each Customer is made aware of, and agrees to, the 1Password Terms or a separate agreement between Customer and 1Password. The Partner shall provide the 1Password Terms to each Customer at the point of sale. Any questions or concerns regarding the 1Password Terms shall be promptly referred to 1Password. 1Password reserves the right to update the 1Password Terms from time to time at its reasonable discretion.

5.25.2 Insurance. Partner agrees to maintain, at its own expense, appropriate insurance coverage throughout the term of this Partner Agreement to safeguard both parties' interests. Such insurance shall include, but is not limited to, general liability, cyber liability, professional liability, and any other coverage necessary to fulfill the obligations under this Partner Agreement. All policies must be issued by insurers with a minimum rating of A- by A.M. Best or a comparable rating from another reputable rating agency. Upon request, the Partner shall promptly provide certificates of insurance as evidence of such coverage. Additionally, the Partner agrees to notify the 1Password immediately of any cancellation, non-renewal, or material changes to the insurance policies.

5.35.3 Data Processing Agreement. Partner agrees to notify Customers that the Services are provided by 1Password and that we may process and transfer, use, modify, reproduce, and distribute Customer Data in order to provide and operate the Services.

·The Partner acknowledges and agrees that any processing of personally identifying information shall be in accordance with Customer instructions and governed by the terms of the 1Password Data Processing Addendum ("DPA"), available at https://1passwordstatic.com/files/legal-center/1Password-Online-MSP-DPA.pdf. The DPA is hereby incorporated into and forms an integral part of this Partner Agreement.

5.45.4 Sales and Marketing Efforts. Partner shall promote and distribute the Service in accordance with the following terms: (a) Partner shall represent the Services accurately and fairly, refraining from all misleading or unethical business practices; (b) Partner shall maintain marketing and customer service standards that are appropriate to maintain high-quality Services and to reflect favorably on both the Partner and 1Password's reputation; (c) Partner shall comply with all applicable local, state, provincial, federal, and foreign laws in respect to the marketing communications, promotion and resale of the Services; and (d) Partner shall include in all advertising all applicable copyright and trademark notices as they appear on or in the Services, or as otherwise reasonably directed by 1Password. Partner shall not make any representations as to the functionality or performance of the Services or any related documentation or marketing materials, except as permitted under the Partner Program or as specifically approved in writing by 1Password. Neither Party will issue any press release, public announcement, or public statement about this Partner Agreement or the subject matters related to this Partner Agreement without the other Party's prior written approval (email sufficient).

5.55.5 Training Requirements. Partner will: (a) meet any standards mutually agreed upon by the Parties for displaying, demonstrating, and explaining the use and operation of the Services to customers and potential customers; and (b) maintain an adequate staff of trained sales and support personnel, meeting the minimum requirements agreed to by the parties in writing.

66. Fees and Payment

6.16.1 Payment. Partner shall pay 1Password within thirty (30) calendar days of invoice date, regardless of whether Partner has been paid by Customer. Partner is solely responsible for the collection of amounts owed to Partner by Customer for the Services and the failure to collect money owed by Customer does not excuse Partner's performance to pay 1Password. 1Password shall have no obligation to cease to provide or suspend the Services to any Customer.

6.26.2 Pricing. 1Password will periodically provide Partner with an updated price list for the Services, which may be revised at 1Password's sole discretion. Partner shall collaborate with 1Password to set pricing for the Services sold by Partner. Under no circumstances shall Partner sell any Services below any minimum price established by 1Password.

6.36.3 Partner Margin. Partners are responsible for setting their pricing for Services. 1Password has no responsibility to Partner for, and makes no promises or commitments to Partner regarding, Partner's success in the Partner Program, Partner's profits or margins, or its ability to continue to participate in the Partner Program or sell to any Customers in the future.

6.46.4 Taxes. Any amounts payable by Partner to 1Password under this Partner Agreement that arise as the result of any activity under this Agreement shall be exclusive of Taxes. Such Taxes are in addition to any other amounts owing. If Partner is exempt from payment of such Taxes, Partner must provide 1Password with an original certificate (or other equivalent documentation) that satisfies applicable legal requirements attesting to tax-exempt status. Tax exemption will only apply from and after the date 1Password receives such certificate. Partners are responsible for all applicable Taxes that arise from or as a result of any activities under this Partner Agreement or with respect to Partners dealings with Customers. If Taxes are not collected by 1Password in respect of amounts paid by Partner to 1Password for Customer transactions, Partner is responsible for determining if Taxes are payable on such transactions, and if so, paying Taxes to the appropriate tax authorities. Any amounts owing to 1Password by Partner under this Partner Agreement will be free and clear of, and without deduction or withholding for, any withholding taxes of any taxing jurisdictions. If withholding taxes must be withheld from amounts owing to 1Password, such payable will be increased such that the amount received by 1Password is the same as it would have been if no withholding taxes were withheld.

6.56.5 Bundling. The Partner may sell the Services either as a standalone offering or bundled with other Partner products or services.

77. Request for Information and Audits

7.17.1 Audits. Partner shall maintain complete and accurate accounting records, in accordance with generally accepted accounting principles, to document the resale of Services to Customers. 1Password reserves the right to audit these records periodically. Such audits will generally be limited to once per year, and only in cases where there is reasonable doubt concerning the Partner's accounting. Audits will be conducted during Partner's regular business hours, at 1Password's expense, with a minimum of two weeks' written notice provided.

88. Beta Products

8.18.1 Pre-Released Services. If the applicable Purchase Order indicates that the licenses granted are for services that are not yet commercially available ("Pre-Released Services"), 1Password grants the Partner a temporary, non-exclusive, non-transferable, and revocable license to resell the Pre-Released Services and to the associated documentation, as provided by 1Password, solely for internal evaluation purposes. 1Password may terminate the Partner's or Customer's right to use the Pre-Released Services at any time, at its sole discretion. The Partner's or Customer's use of the Pre-Released Services is limited to thirty (30) calendar days unless otherwise specified in the Purchase Order.

8.28.2 No Guarantee of Continuity. The Partner acknowledges and agrees that (i) 1Password has not promised or guaranteed that the Pre-Released Services will be announced or made generally available in the future; (ii) 1Password has no obligation, express or implied, to announce or introduce the Pre-Released Services; and (iii) any use of the Pre-Released Services is entirely at the Customer's own risk.

99. Term and Termination

9.19.1 Term. This Partner Agreement shall commence on the Effective Date and continue until terminated in accordance with the terms of this Partner Agreement (the "Term").

9.29.2 Termination without Cause. Either Party may terminate this Partner Agreement at any time without cause, which termination shall become effective upon thirty (30) days' prior written notice to the other Party.

9.39.3 Termination for Cause. Either Party may terminate this Partner Agreement immediately upon written notice to the other party in the event of a material breach of any provision of this Partner Agreement by the other party, provided that such breach is not cured within thirty (30) days following receipt of written notice specifying the breach in detail. If the breach is not capable of being cured, the non-breaching party may terminate this Partner Agreement immediately upon notice.

9.49.4 Effects of Termination. Upon termination of this Partner Agreement, the Partner shall immediately cease all marketing and promotional activities related to the Services. Neither Party shall be held liable for any damages resulting from the valid termination of this Partner Agreement. Any such termination shall not affect any claims arising prior to the effective date of termination. Upon termination of this Partner Agreement, all sales, transactions, or obligations made or incurred by Reseller prior to the effective date of termination shall continue to be honored and performed in accordance with their respective terms. Termination of this Partner Agreement shall not relieve either Party of any rights or obligations accrued before such termination, including but not limited to the fulfillment of pending orders, payments due, and compliance with applicable terms and conditions of any sales or commitments made.

1010. Representations and Warranties

10.110.1 Binding Obligation. Each Party represents and warrants to the other Party that it has the right to enter into this Partner Agreement, and that this Partner Agreement constitutes a valid binding obligation of such party, enforceable against such party in accordance with its terms and does not conflict with or violate any agreements such party has with any third party.

10.210.2 Not Binding on Other Party. Each Party shall not make a representation, warranty, or other statement that purports to be on behalf of the other Party that is not specifically authorized in writing by a person authorized to bind the other Party.

1111. Indemnification

11.111.1 1Password Indemnity. 1Password will defend, indemnify and hold Partner against any claim, demand, suit or proceeding made or brought against Partner by a third party alleging that the Services infringes or misappropriates the intellectual property rights of such third party (an "Infringement Claim"), and will indemnify Partner from any damages, attorney fees and costs finally awarded against Partner as a result of, or for amounts paid by Partner under a settlement approved by 1Password in writing of, an Infringement Claim, provided Partner (a) promptly gives 1Password written notice of the Infringement Claim, (b) gives 1Password sole control of the defense and settlement of the Infringement Claim (except that 1Password may not settle any Infringement Claim unless it unconditionally releases Partner of all liability), and (c) gives 1Password all reasonable assistance, at 1Password's expense. If 1Password receives information about an infringement or misappropriation claim related to the Services, 1Password may in its discretion and at no cost to Partner (i) modify the Services so that they are no longer claimed to infringe or misappropriate, (ii) obtain a license for Partner's or Customer's (as applicable) continued use of that Service in accordance with this Partner Agreement; or (iii) terminate any of Partner's or Customer's (as applicable) rights for that Service upon thirty (30) days' written notice and refund Partner or Customer (as applicable) any prepaid fees covering the remainder of the term of the terminated Services. The above defense and indemnification obligations do not apply to the extent a Claim Against Partner arises from (i) Partner's breach of this Partner Agreement, the Documentation or applicable Purchase Orders or Order Forms; or (ii) the use or combination of the Services, or any part thereof with software, hardware, data, or processes not provided by 1Password, if the Services, or use thereof, would not infringe without such combination.

11.211.2 Partner Indemnity. Partner shall defend, indemnify and hold 1Password and its subsidiaries and its directors, officers, shareholders, employees, consultants, affiliates and agents harmless against any and all damages, liability, costs and expenses (including legal fees and expenses) arising out of any third party (including from any Customer or Authorized User) claim, suit, action, damages, costs, losses, expenses and other liabilities arising from or in connection with: (a)any representations or warranties made by Partner in respect to the Services or any portions thereof beyond those authorized in this Partner Agreement; (b) any violation of International Trade Control Laws by Partner, its employees, or agents acting on its behalf. Partner's obligations in this Section 11.2 include, without limitation settlement at Partner's expense and payment of judgments finally awarded by a court of competent jurisdiction, as well as payment of court costs and other reasonable expenses.

11.311.3 Conditions. The indemnitor's obligations in Sections 11.1 and 11.2 are conditioned on the indemnitee: (a) promptly giving written notice of the claim to the indemnitor (although a delay of notice will not relieve the indemnitors of its obligations under this clause except to the extent that the indemnity is prejudiced by such delay); (b) giving the indemnitor sole control of the defence and settlement of the claim (although indemnitor may not settle any claim unless it unconditionally releases indemnitee of all liability); and (c) providing to the indemnitor, at the indemnitor's cost, all reasonable assistance. This Section 11 states each indemnitee's exclusive remedies and the indemnitor's sole obligations for all third-party Claims related to the subject matter of this Section.

1212. Limitation of Liability

12.112.1 CONSEQUENTIAL DAMAGES WAIVER. IN NO EVENT SHALL EITHER PARTY BE LIABLE TO THE OTHER FOR INDIRECT, SPECIAL, INCIDENTAL, CONSEQUENTIAL, PUNITIVE OR EXEMPLARY DAMAGES OF ANY KIND INCLUDING, WITHOUT LIMITATION, LOSS OF USE, LOSS OF DATA, LOSS OF SALES OR PROFIT, FAILURE TO REALIZE EXPECTED SAVINGS, BUSINESS INTERRUPTION, LOSS OF BUSINESS, PERSONAL INJURY, PROPERTY DAMAGE, ANY LOSS ASSOCIATED WITH OR ARISING IN RELATION TO ANY 1PASSWORD SERVICES OR DELIVERABLES; OR ANY LOSS OR FAILURE RESULTING FROM THE USE OF OR INABILITY TO USE ANY 1PASSWORD SERVICES OR DELIVERABLES, OR THE PROVISION OF OR FAILURE TO PROVIDE SUPPORT: (A) WHETHER OR NOT SUCH LOSSES OR FAILURES ARE CONSIDERED DIRECT OR INDIRECT, ARE REASONABLY FORESEEABLE, OR SUCH PARTY HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH LOSS OR FAILURE TO REALIZE; AND (B) HOWEVER CAUSED, INCLUDING, WITHOUT LIMITATION, THOSE RESULTING FROM 1PASSWORD'S SERVICES OR DELIVERABLES, AND (C) REGARDLESS OF THE THEORY OF LIABILITY INCLUDING, WITHOUT LIMITATION, WHETHER THE ACTION AROSE IN CONTRACT (INCLUDING, WITHOUT LIMITATION, FROM A FUNDAMENTAL BREACH, OR BREACH OF A CONDITION, FUNDAMENTAL TERM OR WARRANTY); OR IN TORT (INCLUDING, WITHOUT LIMITATION, NEGLIGENCE); OR OTHERWISE.

12.212.2 LIABILITY CAP. EXCEPT AS SET OUT IN SECTION 12.2, EACH PARTY'S TOTAL AGGREGATE LIABILITY ARISING OUT OF OR RELATING TO THIS PARTNER AGREEMENT (INCLUDING, BUT NOT LIMITED TO, CLAIMS FOR NEGLIGENCE, STRICT LIABILITY, BREACH OF CONTRACT, MISREPRESENTATION, OR TORT CLAIMS) WILL NOT EXCEED THE GREATER OF (A) WITH RESPECT TO ANY CLAIM OR SET OF CLAIMS RELATING TO THE SAME EVENTS, THE AMOUNT ACTUALLY PAID OR PAYABLE BY PARTNER TO 1PASSWORD FOR THE APPLICABLE SERVICES IN THE TWELVE (12) MONTHS IMMEDIATELY PRECEDING THE EVENT GIVING RISE TO THE CLAIM, OR (B) $100,000 USD.

12.312.3 SUPERCAP. EACH PARTY'S TOTAL AGGREGATE LIABILITY WILL NOT EXCEED THE GREATER OF FIVE (5) TIMES FEES PAID TO 1PASSWORD BY PARTNER IN THE PREVIOUS TWELVE (12) MONTHS FOR (I) A PARTY'S BREACH OF THE CONFIDENTIALITY OBLIGATIONS UNDER SECTION 13 OR (II) INDEMNIFICATION OBLIGATIONS RELATED TO AN INFRINGEMENT CLAIM UNDER SECTION 11.

1313. Confidentiality

13.113.1 Confidential Information. The Parties acknowledge that a Party (the "Receiving Party") may receive Confidential information relating to the other Party (the "Disclosing Party"). A Receiving Party will use the same or greater degree of care in safeguarding Confidential Information as it uses for its own Confidential Information of like importance, but no less than reasonable care. A Receiving Party is permitted to disclose Confidential Information to its Affiliates, employees, subcontractors, and agents who, in each case, have a need to know to perform the Receiving Party's obligations or exercise its rights under this Partner Agreement, and who are subject to confidentiality obligations at least as protective of the Disclosing Party's Confidential Information as those contained in this Partner Agreement. The Receiving Party is liable for its Affiliates', employees', subcontractors', and agents' compliance with the terms of this Section 13. Upon request, all copies and excerpts of Confidential Information will be promptly returned to the Disclosing Party, or securely erased or destroyed, excepting any archived copies, which will remain subject to these confidentiality provisions

13.213.2 Exclusions. A Receiving Party's obligation of confidentiality and restriction on use will not apply to Confidential Information if, and only to the extent that it can demonstrate, the Confidential Information: (a) was known to the Receiving Party before receipt from the Disclosing Party; (b) was generally available to the public (or becomes so) without the fault or negligence of the Receiving Party; (c) was rightfully received by the Receiving Party from a third Party without a duty of confidentiality; or (d) was independently developed by the Receiving Party without any use of or reference to the Disclosing Party's Confidential Information

13.313.3 Compelled Disclosure. If the Receiving Party is served with a subpoena or order issued by a court of competent jurisdiction that requires the disclosure of Confidential Information, the Receiving Party shall, except as prohibited by applicable law, promptly notify the Disclosing Party thereof in writing, in any event before disclosure is made, so that the Disclosing Party may seek an appropriate protective order. To the extent legally permitted, the Receiving Party will consult and cooperate with the Disclosing Party to obtain a protective order or other reliable assurance that confidential treatment will be accorded to the Confidential Information and will otherwise only disclose that portion of the Confidential Information that is required to be disclosed.

13.413.4 Irreparable Harm. The Parties acknowledge and agree that any breach of the terms of Section 13. will cause irreparable harm and damage to the aggrieved Party. The Parties further agree that each Party shall be entitled to pursue injunctive relief to prevent breaches of this Section 13 and to specifically enforce the terms and provisions of this Section 13, in addition to any other remedy to which such Party may be entitled, at law or in equity

13.513.5 Executed Non-Disclosure Agreement. To the extent that Customer has entered into a non-disclosure agreement with 1Password in contemplation of this Partner Agreement (a "NDA"): (i) all Confidential Information disclosed under that NDA is deemed to have been disclosed under this Partner Agreement; (ii) this Partner Agreement is deemed to replace and supersede the NDA; and (iii) the NDA is hereby terminated.

1414. Compliance with Laws

14.114.1 Compliance with Law. Each Party will comply with all Applicable Laws and regulations relating to the performance of its obligations under this Partner Agreement.

14.214.2 Compliance with International Trade Control Laws. Partner certifies that it is eligible to sell Services under applicable International Trade Control Laws and will not use the Services in breach of or contrary to International Trade Control Laws. Partner further certifies that Partner is not, and any of its Affiliates, subsidiaries, directors, or officers: (i) a Restricted Party; (ii) resident in or a national of a Restricted Region, or (iii) part of the Government of Venezuela. Partner will not (a) access, use, deal with, sell, supply, transfer, export, re-export, or otherwise make available, (b) broker the access, use, dealing with, sale, supply, transfer, export, or re-export of, or (c) permit an agent or end-user or any other Party to access, use, deal with, sell, supply, transfer, export, or re-export any part of the Services or 1Password's other technology in violation of International Trade Control Laws, or in a manner that would cause 1Password (or any other Party) to violate International Trade Control Laws. Partner further acknowledges that breach of this Section 14.2 is a material breach of the Partner, which may cause a risk of harm or loss to 1Password or to 1Password's other customers. If at any time Partner is unable to comply with this Section 14.2 during the Term of this Partner Agreement, Partner must notify 1Password in writing immediately. 1Password is not obliged to perform any obligation under this Partner Agreement to the extent the performance of such obligation would breach International Trade Control Laws or expose 1Password to any risk of enforcement action, liability on its part, or punitive or restrictive measures under International Trade Control Laws.

1515. General Provisions

15.115.1 Relationship of the Parties. The Parties are independent contractors. This Partner Agreement does not create nor is it intended to create a partnership, franchise, joint venture, agency, fiduciary, or employment relationship between the Parties. There are no third-party beneficiaries to the Partner Agreement.

15.215.2 Disputes. Any dispute, controversy, or claim arising out of or relating to this Partner Agreement, or the breach hereof, must be referred to senior management of the Parties for good faith discussion and resolution. If any dispute, controversy, or claim cannot be resolved by such good faith discussion between the Parties, then each has all remedies available to them at law and in equity.

15.315.3 Governing Law and Jurisdiction. The Uniform Commercial Code (UCC), the United Nations Convention on Contracts for the International Sale of Goods, and the Uniform Computer Information Transactions Act (UCITA) do not apply to this Partner. This Partner Agreement and all relations, disputes, claims, and other matters arising hereunder (including non-contractual disputes and claims) shall be governed exclusively by, and construed procedurally and substantively, as follows:

·WHERE PARTNER IS LOCATED: Canada Canada GOVERNING LAW - Ontario GOVERNING LAW - Ontario VENUE FOR DISPUTE - Toronto, Ontario VENUE FOR DISPUTE - Toronto, Ontario United States United States GOVERNING LAW - Delaware GOVERNING LAW - Delaware

  • ·VENUE FOR DISPUTE - Wilmington, Delaware

·VENUE FOR DISPUTE - Wilmington, Delaware Asia Asia GOVERNING LAW - Singapore GOVERNING LAW - Singapore VENUE FOR DISPUTE - Singapore VENUE FOR DISPUTE - Singapore

  • ·European Union, United Kingdom, and any region not otherwise set out in this table

·European Union, United Kingdom, and any region not otherwise set out in this table GOVERNING LAW - Ireland GOVERNING LAW - Ireland VENUE FOR DISPUTE - Dublin, Ireland VENUE FOR DISPUTE - Dublin, Ireland

15.415.4 Non-Exclusive Relationship. Nothing in this Partner Agreement shall preclude 1Password from marketing, selling, licensing, leasing or maintaining the Services or any other 1Password products, to or for any other party. Partner recognizes that 1Password may appoint other parties to represent any 1Password's Services, including other parties who may compete with Partner.

15.515.5 Assignment. Neither Party may assign this Partner Agreement without the advance written consent of the other Party, except that each Party may assign this Partner Agreement without consent in connection with a merger, reorganization, acquisition, or other transfer of all or substantially all of its assets or voting securities. Any attempt to transfer or assign this Partner Agreement except as expressly authorized under this section will be void. This Partner Agreement will bind and enure to the benefit of each Party's permitted successors and assigns.

15.615.6 Disputes. Any dispute, controversy, or claim arising out of or relating to this Partner Agreement, or the breach hereof, must be referred to senior management of the Parties for good faith discussion and resolution. If any dispute, controversy, or claim cannot be resolved by such good faith discussion between the Parties, then each has all remedies available to them at law and in equity.

15.715.7 Notices. Any notice or communication under this Partner Agreement must be in writing and sent electronically. Notices are deemed given the first business day after sending by email. Partner must send any notices under this Agreement (including breach notices and warranty and indemnity claims) to 1Password at [email protected], Attn: Chief Legal Officer. Notices to Customers will be sent to the email address on file. 1Password may also provide operational notices regarding the Service or other business-related notices through conspicuous posting of notices

15.815.8 Survival. The following provisions will survive the termination of this Partner Agreement: Sections 4.4, 6, 7, 9.4, 11-5 and all defined terms in this Partner Agreement.

Part BPART B - APPLIES TO ALL RESELLERS

1.11.1 Purchases. Reseller may request a Quote from 1Password for any prospect opportunity. To purchase Services for a Customer, Reseller may either submit a Purchase Order to 1Password, or agree to an Order Form with 1Password. Purchase Orders may be submitted, or Order Forms may be signed by Partner, any time during the Term. Subject to the foregoing, the Purchase Order will contain, at a minimum, the following additional information: (i) description and identification of Services purchased; (ii) Customer information; (iii) quantity of each Authorized User to be purchased; (iv) confirmation of purchase price; and (v) Quote number identifying the applicable Quote. Any Purchase Order for 1Password SaaS Manager will use Managed Identity as the item being purchased. Where the Purchase Order uses Authorized Users or Users rather than Managed Identities for purchases of 1Password SaaS Manager, Authorized User or Users will be deemed to mean Managed Identities. Each Purchase Order will make specific reference to this Partner Agreement, and thereby incorporate the terms of this Partner Agreement. The terms of this Partner Agreement prevail over any terms or conditions contained in any other documentation related to the subject matter of this Partner Agreement and expressly exclude any of Reseller's general terms and conditions contained in any Purchase Order or other document issued by Reseller.

1.21.2 Order Acceptance. 1Password will use commercially reasonable efforts to respond to each Purchase Order within seven (7) business days from receipt thereof, with such acceptance or rejection to be in 1Password's sole discretion. No Purchase Order will be binding on 1Password until accepted (in whole or in part) by 1Password. 1Password may condition acceptance of a Purchase Order or subscription start date after acceptance of a Purchase Order on Reseller's creditworthiness or upfront payment. If 1Password accepts a Purchase Order, 1Password will notify the Reseller promptly in writing.

1.31.3 True Up. In the event that 1Password determines that Reseller's Customer has over deployed the Services such that it is utilizing more Authorized Users then licensed under the Purchase Order, 1Password will notify Reseller in writing of any alleged discrepancy and Reseller agrees to pay such amounts within thirty (30) calendar days from receipt of such notification.

1.41.4 Channel Conflict. 1Password reserves the right, at its sole discretion, to make the final determination, on a good-faith basis, on compensation due, if any, to Reseller related to any particular commercial transaction with a Customer in the event that there exists a conflict between Reseller and any other value-added reseller, distributor, managed service provider, sales agent, or other authorized agent of 1Password.

1.51.5 Pricing, Incentives, Rebates. All pricing, discounts, rebates, and related information for the Services shall be provided to Reseller either through the Partner Portal or separately in writing. Reseller acknowledges and agrees to access and adhere to such information as specified by 1Password, and any updates or modifications to such terms shall be communicated via these channels.

1.61.6 Reseller Data Responsibilities. Each Reseller is responsible for managing the personally identifying information it submits in connection with a Purchase Order or Order Form. Reseller represents and warrants that it has: (i) complied with all applicable laws and contractual obligations in its collection, processing and transfer to 1Password in connection with a Purchase Order or Order Form; (ii) obtained all rights necessary to transfer such Purchase Order or Order Form to 1Password (including any contractual rights owed to third parties); and (iii) obtained valid consent of all individuals whose personal data is contained in such Purchase Order or Order Form and that such individuals have also consented to the intended use of such personal data, including the subsequent transfers to and processing by 1Password. Reseller acknowledges that 1Password may be required to provide personal data to third parties to comply with legally mandated reporting, disclosure, or other legal process requirements. Personally identifying information that 1Password receives in connection with a Purchase Order or Order Form submitted by Reseller will be handled in accordance with Customer instructions or as described in the 1Password Data Protection Addendum (currently available at https://1password.com/legal-center/DPA).

Part CPART C - APPLIES TO ALL MANAGED SERVICE PROVIDERS

1.11.1 License for Managed Services. Subject to the terms of this Partner Agreement, including the payment of applicable fees, 1Password grants Partner the limited, non-exclusive, nontransferable license during the Term to (a) market and demonstrate the Services to potential Managed Customers for use as part of the Managed Services, and (b) open Managed Customer accounts to allow such Managed Customers to access and use the Services, and to permit the Managed Customer to access such Services only as part of the Managed Services. Any demonstrations to Managed Customers will be subject to 1Password's guidelines and restrictions provided from time to time. MSP may only provide the Managed Services and corresponding Services access to Managed Customers directly and not through sub-distributors, other partners, OEM's, or any other third party. MSP is responsible for adding, maintaining and removing the user accounts of its Managed Customers.

1.21.2 Internal Not-For-Resale License. Subject to the terms of the this Partner Agreement, including the payment of fees, 1Password may grant certain MSPs with non-exclusive, nontransferable, revocable subscription licenses for MSP Users ("NFR License"), solely for internal evaluation, demonstration, and training purposes and not for resale, distribution, or commercial use. All use by MSP of the NFR Licenses are subject to the 1Password Terms. 1Password reserves the right to limit the number of NFR Licenses, or remove all previously issued NFR Licenses, available to MSP upon advance notice to the MSP.

1.31.3 MSP Provided Support. MSP will provide its own maintenance and support services to each of its Managed Customers. MSP shall use all reasonable endeavors to attend to Support tickets without reliance on 1Password Maintenance. Notwithstanding the foregoing, 1Password will respond to all reasonable requests for Maintenance from MSP, provided such requests are submitted to 1Password in accordance with the Documentation. For the avoidance of doubt, 1Password will not be obligated to provide Maintenance directly to any Managed Customer.

1.41.4 No Fees or Billing as of Addendum Effective Date. 1Password will charge a Partner a monthly Net Seat Fee in accordance with the pricing disclosed by 1Password to Partner in writing. 1Password may amend the per Net Seat pricing at any time upon 30 days advance notice to the MSP. Any such Net Seat pricing will be applicable solely to Services purchased under Managed Services, and MSP may not apply such price list to any of its other resale activities.

1.51.5 Invoice and Billing. MSPs will be billed monthly in arrears and 1Password will deliver invoices to MSP following the Billing Period.

1.61.6 Aggregated Data. MSP acknowledges that 1Password may collect aggregated and de-identified statistics about MSP and Managed Customer's use of the Services ("Aggregated Data") to improve the Services. Such Aggregated Data may be derived from MSP Data, but will not contain any MSP Data, Customer Confidential Information, personal data (or personally identifiable information), or any data that can be used to identify MSP or any individuals (including Managed Customer and Authorized Users). 1Password may create, reproduce, publicize, or otherwise use such Aggregated Data for internal business purposes (including developing and improving the Services) and will not sell such Aggregated Data.

1.71.7 Implementation and Security Requirements. MSP shall deploy and use the Managed Services strictly in accordance with the Documentation and 1Password's reasonable security standards as provided to MSP from time to time in writing and prevailing best industry practice for a managed services solution and related systems (such as ISO 27001, SOC 2, SSAE or relevant replacement or successor standards then in force). In the event that MSP wishes to deviate from any of the requirements stated therein, it will provide 1Password with a written request describing the proposed change, including a risk analysis of the desired implementation model. 1Password will, in its sole discretion, determine if the deviation is approved or rejected and notify MSP of its decision within ten (10) business days of MSP's complete request. MSP agrees that all licenses and rights granted under this Partner Agreement shall be operated and maintained exclusively by MSP's duly qualified personnel, in a safe and reasonable manner and in accordance with the Documentation.

1.141.14 Data Protection. Where required, when 1Password processes personal data (or personally identifiable information) as part of the Services, 1Password's Partner Data Protection Addendum (currently available at https://1passwordstatic.com/files/legal-center/1Password-Online-MSP-DPA.pdf) (the "Partner DPA") applies and is part of this Partner Agreement. 1Password may update or modify the Partner DPA from time to time upon written notice to MSP. The Parties further agree that the Partner DPA may be amended to comply with changes in Applicable Privacy and Data Protection Laws. Any such updates or modifications will become effective within 10 days after such notice is provided to MSP, unless MSP provides 1Password with written notice of its objection to such updates, in which case the current Partner DPA will remain in effect and 1Password may terminate the Partner Agreement.

1.81.8 Managed Customer Agreements. The MSP will ensure that each of its Managed Customers has agreed to the 1Password Terms prior to gaining access to the Managed Services. In addition to the Managed Customer agreeing to the 1Password Terms, prior to providing Managed Services access to any Managed Customer, Managed Customer and MSP must first enter into a written agreement that permits Managed Customer to access the Services as part of the Managed Services and meets the following criteria ("Customer Agreement"):

  • 1.8.11.8.1 the Customer Agreement may not impose any obligations or liabilities on 1Password;
  • 1.8.21.8.2 the Customer Agreement must be consistent with this Partner Agreement; and
  • 1.8.31.8.3 MSP shall enforce the terms of its Customer Agreements with Managed Customers.

·If either Party becomes aware of a Managed Customer being in breach of the 1Password Terms or the Customer Agreement, it will promptly notify the other Party and the Parties will work together to remediate any risks that such breach may present, including terminating Managed Customer's access to the Managed Services.

1.91.9 Transition Assistance. The MSP agrees to cooperate fully with 1Password to facilitate the seamless transition of any Managed Customer who elects to discontinue procuring Managed Services from MSP. This transition may involve migrating the Managed Customer to another Partner or to a direct account with 1Password. The MSP's obligation to cooperate with such transitions shall also apply in the event that the MSP ceases to offer Managed Services to Managed Customers pursuant to an agreement with 1Password. Such cooperation shall include, but is not limited to, providing necessary information, access to systems, and support to ensure a smooth and efficient transition, minimizing any disruption to the Services used by the Managed Customer.

1.101.10 Certification. Password may, at its discretion, establish and offer a certification program for MSPs. The criteria for eligibility, as well as the scope of benefits and obligations associated with the certification, will be defined and administered by 1Password. 1Password reserves the right to modify, suspend, or revoke any certification granted under this program at any time and for any reason, at its sole discretion.

·Change Log

·2026-01-13: Updated to reflect product rebrand to SaaS Manager

·2025-07-31: Made updates to our Internal Not-For-Resale License terms.

·2025-04-04: Added definition of Managed Identity and removed link to historic Partner Program Agreement. 2024-11-23 2023-07-24

Data Processing Agreement | SaaS Manager | 1Password · data processing agreement
Part of the agreement

Data Processing Agreement | SaaS Manager | 1Password

9,189 words, 262 clausesno date on the pageread 08/10/2026source

·Data Processing Agreement

·Version Number: 1.0.0 Effective Date: May 11th 2023

·This Data Processing Agreement and its Annexes ("DPA") represents the Parties' agreement with respect to the Processing of Personal Data by Trelica on behalf of the Customer in connection with the Services under the Master Subscription Agreement (the "Agreement").

·This DPA is supplemental to, and forms an integral part of, the Agreement and is effective upon its incorporation into the Agreement, which may be specified in the Agreement, an Order Form or an executed amendment to the Agreement. In case of any conflict or inconsistency with the terms of the Agreement, this DPA will take precedence over the terms of the Agreement.

·The term of this DPA will follow the term of the Agreement. Terms not otherwise defined in this DPA will have the meaning as set forth in the Agreement.

11. Definitions

·Controller: means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data.

·Data Protection Laws: means all applicable worldwide legislation relating to data protection and privacy which applies to the respective Party in the role of Processing Personal Data under the Agreement, including without limitation the UK Data Protection Legislation and European Data Protection Laws; in each case as amended, repealed, consolidated or replaced from time to time.

·Data Subject: means the individual to whom Personal Data relates.

·Europe: means the European Union, the European Economic Area and/or their member states, Switzerland and the United Kingdom.

·European Data: means Personal Data that is subject to the protection of European Data Protection Laws.

·European Data Protection Laws: means data protection laws applicable in Europe, including: (i) Regulation 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation) ("GDPR"); (ii) Directive 2002/58/EC concerning the processing of personal data and the protection of privacy in the electronic communications sector; and (iii) applicable national implementations of (i) and (ii); or (iii) GDPR as it forms parts of the United Kingdom domestic law by virtue of Section 3 of the European Union (Withdrawal) Act 2018 ("UK GDPR"); and (iv) Swiss Federal Data Protection Act on 19 June 1992 and its Ordinance ("Swiss DPA"); in each case, as may be amended, superseded or replaced.

·Instructions: means the written, documented instructions issued by a Controller to a Processor, and directing the same to perform a specific or general action with regard to Personal Data (including, but not limited to, depersonalising, blocking, deletion, making available).

·Personal Data: means any information relating to an identified or identifiable individual where such information is contained within Customer Data and is protected similarly as personal data, personal information or personally identifiable information under applicable Data Protection Laws.

·Personal Data Breach: means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data transmitted, stored or otherwise Processed by Trelica and/or its Sub-Processors in connection with the provision of the Services. "Personal Data Breach" will not include unsuccessful attempts or activities that do not compromise the security of Personal Data, including unsuccessful log-in attempts, pings, port scans, denial of service attacks, and other network attacks on firewalls or networked systems.

·Processing: means any operation or set of operations which is performed on Personal Data, encompassing the collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction or erasure of Personal Data. The terms "Process", "Processes" and "Processed" will be construed accordingly.

·Processor: means a natural or legal person, public authority, agency or other body which Processes Personal Data on behalf of the Controller.

·Standard Contractual Clauses: means the standard contractual clauses for Processors annexed to the European Commission's Decision (EU) 2021/914 of 4 June 2021, in the form set out at Annex IV; as may be amended, superseded or replaced.

·Sub-Processor: means any Processor engaged by Trelica to assist in fulfilling its obligations with respect to the provision of the Services under the Agreement.

22. Customer Responsibilities

2.12.1 Compliance with Laws - within the scope of the Agreement and in its use of the services, the Customer will be responsible for complying with all requirements that apply to it under applicable Data Protection Laws with respect to its Processing of Personal Data and the Instructions it issues to Trelica.

2.22.2 The Customer acknowledges and agrees to be solely responsible for:

2.2.12.2.1 the accuracy, quality, and legality of Customer Data and the means by which the Customer acquired Personal Data;

2.2.22.2.2 complying with all necessary transparency and lawfulness requirements under applicable Data Protection Laws for the collection and use of the Personal Data, including obtaining any necessary consents and authorisations;

2.2.32.2.3 ensuring they have the right to transfer, or provide access to, the Personal Data to Trelica for Processing in accordance with the terms of the Agreement (including this DPA);

2.2.42.2.4 ensuring that any Instructions to Trelica regarding the Processing of Personal Data comply with applicable laws, including Data Protection Laws; and

2.2.52.2.5 complying with all laws (including Data Protection Laws) applicable to content created or managed through the Services. The Customer will inform Trelica without undue delay if they are unable to comply with their responsibilities under this 'Compliance with Laws' section or applicable Data Protection Laws.

2.32.3 Controller Instructions - the Parties agree that the Agreement (including this DPA), together with the Customer's use of the Services in accordance with the Agreement, constitute their complete Instructions to Trelica in relation to the Processing of Personal Data, so long as they may provide additional instructions during the Subscription Term that are consistent with the Agreement, the nature and lawful use of the Services.

2.42.4 Security - the Customer is responsible for independently determining whether the data security provided for in the Services adequately meets their obligations under applicable Data Protection Laws secure use of the Services, including protecting the security of Personal Data in transit to and from the Services.

33. Trelica's Obligations

3.13.1 Compliance with Instructions - Trelica will only Process Personal Data for the purposes described in this DPA or as otherwise agreed within the scope of the Customer's lawful Instructions, except where and to the extent otherwise required by applicable law. Trelica is not responsible for compliance with any Data Protection Laws applicable to the Customer that are not generally applicable to Trelica.

3.23.2 Conflict of Laws - if Trelica becomes aware that it cannot Process Personal Data in accordance with the Customer's Instructions due to a legal requirement under any applicable law, Trelica will:

3.2.13.2.1 promptly notify the Customer of that legal requirement to the extent permitted by the applicable law; and

3.2.23.2.2 where necessary, cease all Processing (other than merely storing and maintaining the security of the affected Personal Data) until such time as the Customer issues new Instructions with which Trelica is able to comply. If this provision is invoked, Trelica will not be liable to the Customer under the Agreement for any failure to deliver the Services until such time as the Customer issues new lawful Instructions with regard to the Processing.

3.33.3 Security - Trelica will implement and maintain appropriate technical and organisational measures to protect Personal Data from Personal Data Breaches, as described under Annex II to this DPA ("Security Measures"). Notwithstanding any provision to the contrary, Trelica may modify or update the Security Measures at its discretion provided that such modification or update does not result in a material degradation in the protection offered by the Security Measures.

3.43.4 Confidentiality - Trelica will ensure that any personnel authorised to Process Personal Data on its behalf is subject to appropriate confidentiality obligations (whether a contractual or statutory duty) with respect to that Personal Data.

3.53.5 Personal Data Breaches - Trelica will notify the Customer without undue delay after becoming aware of any Personal Data Breach and will provide timely information relating to the Personal Data Breach as it becomes known or reasonably requested by the Customer. Where required by Data Protection Laws, and at the Customer's request, Trelica will promptly provide such reasonable assistance as necessary to enable the Customer to notify relevant Personal Data Breaches to competent authorities and/or affected Data Subjects.

3.63.6 Deletion or Return of Personal Data - Trelica will delete or return all Customer Data, including Personal Data (including copies thereof) Processed pursuant to this DPA, on termination of the Agreement or expiration of the Services. This term shall apply except where Trelica is required by applicable law to retain some or all of the Customer Data.

44. Data Subject Requests

·A list of identities with any associated Personal Data is available within the Services and includes features to view, edit and delete. The Customer can use these features to meet obligations relating to responding to requests from Data Subjects wishing to exercise their rights under applicable Data Protection Laws ("Data Subject Requests").

·To the extent the Customer is unable to independently address a Data Subject Request through the Services, Trelica will upon written request provide reasonable assistance to respond to any Data Subject Requests or requests from data protection authorities relating to the Processing of Personal Data under the Agreement. The Customer is responsible for any commercially reasonable costs arising from this assistance.

·In the event a Data Subject Request is made directly to Trelica, the Customer will be promptly informed and Trelica will advise the Data Subject to submit their request directly to the Customer. The Customer is solely responsible for responding to any such Data Subject Requests or communications involving Personal Data.

55. Sub-Processors

·The Customer hereby provides its prior, general authorisation for Trelica to:

5.15.1 appoint sub-processors to process the Agreement Personal Data (including those sub-processors listed at https://1password.com/legal/saas-manager/third-party-sub-processors as may be updated from time to time), provided that Trelica:

5.1.15.1.1 will impose data protection terms on the Sub-Processors that provide at least the same level of protection for Personal Data as those in this DPA (including, where appropriate, the Standard Contractual Clauses), to the extent applicable to the nature of the services provided by such Sub-Processors;

5.1.25.1.2 remain responsible for each Sub-Processor's compliance with the obligations of this DPA and for any acts or omissions of such Sub-Processor that cause Trelica to breach any of its obligations under this DPA; and

5.1.35.1.3 shall notify the Customer of any intended changes concerning the addition or replacement of the sub-processors.

66. Data Transfers

·To the extent that any Customer Instruction requires data transfer, all applicable transfers of Personal Data outside its country of origin will be made in compliance with the requirements of Data Protection Laws.

77. Additional Provisions for European Data

7.17.1 Scope - this 'Additional Provisions for European Data' section shall apply only with respect to European Data.

7.27.2 Roles of the Parties - when Processing European Data in accordance with the Customer's Instructions, the Parties acknowledge and agree that the Customer is the Controller of European Data and Trelica is the Processor.

7.37.3 If Trelica believes that the Customer Instruction infringes European Data Protection Laws (where applicable), Trelica will inform the Customer without delay.

7.47.4 Objection to New Sub-Processors - the Customer will be notified of any intended addition or replacement of the sub-processors and be given 30 days to submit to Trelica a written objection, after which period and if no objection has been received, the Customer is assumed to have given consent. If the Customer objects, the Customer and Trelica will negotiate in good faith to seek a mutually agreeable solution. If a solution is not agreed within 30 days either Party has the right to immediately terminate the Agreement on written notice to the other Party; and (but without prejudice to any fees incurred by the Customer prior to suspension or termination). The Parties agree that by complying with this clause 7.4, Trelica fulfils its obligations under Sections 9 of the Standard Contractual Clauses.

7.57.5 Sub-Processor Agreements - for the purposes of Clause 9(c) of the Standard Contractual Clauses, the Customer acknowledges that Trelica may be restricted from disclosing Sub-Processor agreements but shall use reasonable efforts to require any appointed Sub-Processor to permit it to disclose the Sub-Processor agreement and shall provide (on a confidential basis) all reasonably available information.

7.67.6 Data Protection Impact Assessments and Consultation with Supervisory Authorities - to the extent that the required information is reasonably available to Trelica, and the Customer does otherwise have access to the required information, Trelica will provide reasonable assistance with any data protection impact assessments, and prior consultations with supervisory authorities or other competent data privacy authorities to the extent required by European Data Protection Laws.

7.77.7 Transfer Mechanisms for Data Transfers - to the extent that any Customer Instruction requires transfers of any Personal Data to any country or recipient not recognised as providing an adequate level of protection for Personal Data (within the meaning of applicable European Data Protection Laws), transfers will only occur if the Parties ensure all such measures are taken as is necessary to be compliant with applicable European Data Protection Laws. Such measures may include (without limitation) transferring such data to a recipient that is covered by a suitable framework or other legally adequate transfer mechanism recognised by the relevant authorities or courts as providing an adequate level of protection for Personal Data, to a recipient that has achieved binding corporate rules authorization in accordance with European Data Protection Laws, or to a recipient that has executed appropriate standard contractual clauses in each case as adopted or approved in accordance with applicable European Data Protection Laws.

7.7.17.7.1 The Parties acknowledge and agree the following:

7.7.1.17.7.1.1 to abide by and process European Data in compliance with the Standard Contractual Clauses;

7.7.1.27.7.1.2 for the purposes of the Standard Contractual Clauses:

·a. Trelica will be the "data importer" and the Customer will be the "data exporter";

·b. the Annexes of the Standard Contractual Clauses shall be populated with the relevant information set out in Annex I and Annex II of this DPA;; and

·c. if and to the extent the Standard Contractual Clauses conflict with any provision of this DPA, the Standard Contractual Clauses will prevail to the extent of such conflict.

7.7.1.37.7.1.3 to the extent that and for so long as the Standard Contractual Clauses as implemented in accordance with this DPA cannot be relied on by the Parties to lawfully transfer Personal Data in compliance with the UK GDPR, the applicable standard data protection clauses issued, adopted or permitted under the UK GDPR shall be incorporated by reference, and the annexes, appendices or tables of such clauses shall be deemed populated with the relevant information set out in Annex I and Annex II of this DPA; and

7.7.1.47.7.1.4 if for any reason Trelica cannot comply with its obligations under the Standard Contractual Clauses or is breach of any warranties under the Standard Contractual Clauses, and the Customer intends to suspend the transfer of European Data to Trelica or terminate the Standard Contractual Clauses, the Customer agrees to provide Trelica with reasonable notice to cure such non-compliance and reasonably cooperate with Trelica to identify what additional safeguards, if any, may be implemented to remedy such non-compliance. If Trelica is unable to address the non-compliance, the Customer may suspend or terminate the Agreement without liability to either Party (but without prejudice to any fees the Customer has incurred prior to such suspension or termination).

7.87.8 Demonstration of Compliance - Trelica will make available to the Customer all information reasonably necessary to demonstrate compliance with this DPA. In order to verify compliance with this DPA and provided that the Customer shall not exercise any of one of these rights more than once in any 12-month rolling period, unless there are reasonable grounds to suspect non-compliance with the DPA, Trelica shall upon written request:

7.8.17.8.1 allow for and contribute to audits, including inspections conducted by the Customer or a third party auditor;

7.8.27.8.2 supply (on a confidential basis) summary copies of penetration testing report(s); and

7.8.37.8.3 provide written responses (on a confidential basis) to all reasonable requests for information.

88. General Provisions

8.18.1 Variations - Trelica reserves the right to make updates and changes to this DPA pursuant to section 17 (Variation) of the Master Subscription Agreement.

8.28.2 Severability - if any individual provisions of this DPA are determined to be invalid or unenforceable, the validity and enforceability of the other provisions of this DPA will not be affected.

8.38.3 Limitation of Liability - each Party's liability, taken in aggregate, arising out of or related to this DPA and the Standard Contractual Clauses (where applicable), whether in contract, tort or under any other theory of liability, will be subject to the limitations and exclusions of liability set out in section 12 (Limitation of Liability) of the Master Subscription Agreement. In no event shall either Party's liability be limited with respect to any individual's data protection rights under this DPA (including the Standard Contractual Clauses) or otherwise.

8.48.4 Governing Law - this DPA will be governed by and construed in accordance with section 26 (Governing Law & Jurisdiction) of the Master Subscription Agreement.

Annex IANNEX I - Details of Data Processing

·A. List of Parties

·DATA EXPORTER:

  • ·Organisation Name - The Customer, as set out in the Order Form

·Organisation Name - The Customer, as set out in the Order Form Role - Controller Role - Controller

  • ·Organisation Address - The Customer's address, as set out in the Order Form
  • ·Contact Details - The Customer's contact details, as set out in the Order Form

·DATA IMPORTER: Organisation Name - Trelica Limited Organisation Name - Trelica Limited Role - Processor Role - Processor

  • ·Organisation Address - First Floor, Victory House, Vision Park, Chivers Way, Histon, Cambridge, CB24 9ZR, UK
  • ·Contact Details - Richard Kirby, Data Protection Officer, [email protected]

·B. Description of Processing

·Requirement: Subject matter of processing Subject matter of processing

  • ·Details: Trelica's provision of the Services to the Customer in accordance with the Agreement.

·Details: Trelica's provision of the Services to the Customer in accordance with the Agreement. Duration of processing Duration of processing

  • ·Details: The personal data will be processed for the duration of the Subscription Term.

·Details: The personal data will be processed for the duration of the Subscription Term. Frequency of transfer Frequency of transfer

  • ·Details: Continuous.

·Details: Continuous. Nature and purpose of processing Nature and purpose of processing

  • ·Details: For the purpose of providing the Services to the Customer in accordance with the Agreement.

·Details: For the purpose of providing the Services to the Customer in accordance with the Agreement. Categories of Personal Data Categories of Personal Data

  • ·Includes:
  • ·Name;
  • ·E-mail address;
  • ·Roles assigned in different applications that are monitored by the Services;
  • ·Date of last login or last activity from different applications that are monitored by the Services;
  • ·IP address if the person signs in to Trelica; and
  • ·Any other personal data provided to Trelica for the performance of the Services in accordance with the Agreement.
  • ·Survey Functionality: In relation to any functionality in the Services which permits the Customer to create, distribute, manage, and request responses to surveys from its employees or any other third party ("Survey Functionality"), any other personal data that may be captured by or on behalf of the Customer through such Survey Functionality.

·Survey Functionality: In relation to any functionality in the Services which permits the Customer to create, distribute, manage, and request responses to surveys from its employees or any other third party ("Survey Functionality"), any other personal data that may be captured by or on behalf of the Customer through such Survey Functionality. Categories of Data Subject Categories of Data Subject

  • ·Includes:
  • ·The Customer's personnel.
  • ·Survey Functionality: In relation to any Survey Functionality, any other personal data that may be captured by or on behalf of the Customer through such Survey Functionality.

100C. Competent Supervisory Authority

·For the purposes of the Standard Contractual Clauses, the supervisory authority that shall act as competent supervisory authority is either (i) where Customer is established in an EU Member State, the supervisory authority responsible for ensuring Customer's compliance with the GDPR; (ii) where Customer is not established in an EU Member State but falls within the extra-territorial scope of the GDPR and has appointed a representative, the supervisory authority of the EU Member State in which Customer's representative is established; or (iii) where Customer is not established in an EU Member State but falls within the extra-territorial scope of the GDPR without having to appoint a representative, the supervisory authority of the EU Member State in which the Data Subjects are predominantly located. In relation to Personal Data that is subject to the UK GDPR or Swiss DPA, the competent supervisory authority is the UK Information Commissioner or the Swiss Federal Data Protection and Information Commissioner (as applicable).

Annex IIANNEX II - Security Measures

·As detailed in Trelica's Security Practices available here https://1password.com/legal/saas-manager/security-practices

Annex IIIANNEX III - List of Sub-Processors

·As detailed here https://1password.com/legal/saas-manager/third-party-sub-processors

Annex IVANNEX IV - Standard Contractual Clauses

·Module Two: Transfer Controller to Processor (C2P)

·SECTION I

1Clause 1 Purpose and scope

·(a) The purpose of these standard contractual clauses is to ensure compliance with the requirements of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation) for the transfer of personal data to a third country.

·(b) The Parties:

·(i) the natural or legal person(s), public authority/ies, agency/ies or other body/ies (hereinafter "entity/ies") transferring the personal data, as listed in Annex I.A. (hereinafter each "data exporter"), and

·(ii) the entity/ies in a third country receiving the personal data from the data exporter, directly or indirectly via another entity also Party to these Clauses, as listed in Annex I.A. (hereinafter each "data importer")

·have agreed to these standard contractual clauses (hereinafter: "Clauses").

·(c) These Clauses apply with respect to the transfer of personal data as specified in Annex I.B.

·(d) The Appendix to these Clauses containing the Annexes referred to therein forms an integral part of these Clauses. Clause 2 Effect and invariability of the Clauses

·(a) These Clauses set out appropriate safeguards, including enforceable data subject rights and effective legal remedies, pursuant to Article 46(1) and Article 46 (2)(c) of Regulation (EU) 2016/679 and, with respect to data transfers from controllers to processors and/or processors to processors, standard contractual clauses pursuant to Article 28(7) of Regulation (EU) 2016/679, provided they are not modified, except to select the appropriate Module(s) or to add or update information in the Appendix. This does not prevent the Parties from including the standard contractual clauses laid down in these Clauses in a wider contract and/or to add other clauses or additional safeguards, provided that they do not contradict, directly or indirectly, these Clauses or prejudice the fundamental rights or freedoms of data subjects.

·(b) These Clauses are without prejudice to obligations to which the data exporter is subject by virtue of Regulation (EU) 2016/679. Clause 3 Third-party beneficiaries

·(a) Data subjects may invoke and enforce these Clauses, as third-party beneficiaries, against the data exporter and/or data importer, with the following exceptions:

·(i) Clause 1, Clause 2, Clause 3, Clause 6, Clause 7;

·(ii) Clause 8 - Clause 8.1(b), 8.9(a), (c), (d) and (e);

·(iii) Clause 9 - Clause 9(a), (c), (d) and (e);

·(iv) Clause 12 - Clause 12(a), (d) and (f);

·(v) Clause 13;

·(vi) Clause 15.1(c), (d) and (e);

·(vii) Clause 16(e);

·(viii) Clause 18 - Clause 18(a) and (b).

·(b) Paragraph (a) is without prejudice to rights of data subjects under Regulation (EU) 2016/679. Clause 4 Interpretation

·(a) Where these Clauses use terms that are defined in Regulation (EU) 2016/679, those terms shall have the same meaning as in that Regulation.

·(b) These Clauses shall be read and interpreted in the light of the provisions of Regulation (EU) 2016/679.

·(c) These Clauses shall not be interpreted in a way that conflicts with rights and obligations provided for in Regulation (EU) 2016/679. Clause 5 Hierarchy

·In the event of a contradiction between these Clauses and the provisions of related agreements between the Parties, existing at the time these Clauses are agreed or entered into thereafter, these Clauses shall prevail. Clause 6 Description of the transfer(s)

·The details of the transfer(s), and in particular the categories of personal data that are transferred and the purpose(s) for which they are transferred, are specified in Annex I.B. Clause 7 Docking clause

·(a) An entity that is not a Party to these Clauses may, with the agreement of the Parties, accede to these Clauses at any time, either as a data exporter or as a data importer, by completing the Appendix and signing Annex I.A.

·(b) Once it has completed the Appendix and signed Annex I.A, the acceding entity shall become a Party to these Clauses and have the rights and obligations of a data exporter or data importer in accordance with its designation in Annex I.A.

·(c) The acceding entity shall have no rights or obligations arising under these Clauses from the period prior to becoming a Party.

·SECTION II - OBLIGATIONS OF THE PARTIES

8Clause 8 Data protection safeguards

·The data exporter warrants that it has used reasonable efforts to determine that the data importer is able, through the implementation of appropriate technical and organisational measures, to satisfy its obligations under these Clauses. 8.1 Instructions

·(a) The data importer shall process the personal data only on documented instructions from the data exporter. The data exporter may give such instructions throughout the duration of the contract.

·(b) The data importer shall immediately inform the data exporter if it is unable to follow those instructions. 8.2 Purpose limitation

·The data importer shall process the personal data only for the specific purpose(s) of the transfer, as set out in Annex I.B, unless on further instructions from the data exporter. 8.3 Transparency

·On request, the data exporter shall make a copy of these Clauses, including the Appendix as completed by the Parties, available to the data subject free of charge. To the extent necessary to protect business secrets or other confidential information, including the measures described in Annex II and personal data, the data exporter may redact part of the text of the Appendix to these Clauses prior to sharing a copy, but shall provide a meaningful summary where the data subject would otherwise not be able to understand its content or exercise his/her rights. On request, the Parties shall provide the data subject with the reasons for the redactions, to the extent possible without revealing the redacted information. This Clause is without prejudice to the obligations of the data exporter under Articles 13 and 14 of Regulation (EU) 2016/679. 8.4 Accuracy

·If the data importer becomes aware that the personal data it has received is inaccurate, or has become outdated, it shall inform the data exporter without undue delay. In this case, the data importer shall cooperate with the data exporter to erase or rectify the data.

8.58.5 Duration of processing and erasure or return of data

·Processing by the data importer shall only take place for the duration specified in Annex I.B. After the end of the provision of the processing services, the data importer shall, at the choice of the data exporter, delete all personal data processed on behalf of the data exporter and certify to the data exporter that it has done so, or return to the data exporter all personal data processed on its behalf and delete existing copies. Until the data is deleted or returned, the data importer shall continue to ensure compliance with these Clauses. In case of local laws applicable to the data importer that prohibit return or deletion of the personal data, the data importer warrants that it will continue to ensure compliance with these Clauses and will only process it to the extent and for as long as required under that local law. This is without prejudice to Clause 14, in particular the requirement for the data importer under Clause 14(e) to notify the data exporter throughout the duration of the contract if it has reason to believe that it is or has become subject to laws or practices not in line with the requirements under Clause 14(a). 8.6 Security of processing

·(a) The data importer and, during transmission, also the data exporter shall implement appropriate technical and organisational measures to ensure the security of the data, including protection against a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access to that data (hereinafter "personal data breach"). In assessing the appropriate level of security, the Parties shall take due account of the state of the art, the costs of implementation, the nature, scope, context and purpose(s) of processing and the risks involved in the processing for the data subjects. The Parties shall in particular consider having recourse to encryption or pseudonymisation, including during transmission, where the purpose of processing can be fulfilled in that manner. In case of pseudonymisation, the additional information for attributing the personal data to a specific data subject shall, where possible, remain under the exclusive control of the data exporter. In complying with its obligations under this paragraph, the data importer shall at least implement the technical and organisational measures specified in Annex II. The data importer shall carry out regular checks to ensure that these measures continue to provide an appropriate level of security.

·(b) The data importer shall grant access to the personal data to members of its personnel only to the extent strictly necessary for the implementation, management and monitoring of the contract. It shall ensure that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

·(c) In the event of a personal data breach concerning personal data processed by the data importer under these Clauses, the data importer shall take appropriate measures to address the breach, including measures to mitigate its adverse effects. The data importer shall also notify the data exporter without undue delay after having become aware of the breach. Such notification shall contain the details of a contact point where more information can be obtained, a description of the nature of the breach (including, where possible, categories and approximate number of data subjects and personal data records concerned), its likely consequences and the measures taken or proposed to address the breach including, where appropriate, measures to mitigate its possible adverse effects. Where, and in so far as, it is not possible to provide all information at the same time, the initial notification shall contain the information then available and further information shall, as it becomes available, subsequently be provided without undue delay.

·(d) The data importer shall cooperate with and assist the data exporter to enable the data exporter to comply with its obligations under Regulation (EU) 2016/679, in particular to notify the competent supervisory authority and the affected data subjects, taking into account the nature of processing and the information available to the data importer. 8.7 Sensitive data

·Where the transfer involves personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, genetic data, or biometric data for the purpose of uniquely identifying a natural person, data concerning health or a person's sex life or sexual orientation, or data relating to criminal convictions and offences (hereinafter "sensitive data"), the data importer shall apply the specific restrictions and/or additional safeguards described in Annex I.B. 8.8 Onward transfers

·The data importer shall only disclose the personal data to a third party on documented instructions from the data exporter. In addition, the data may only be disclosed to a third party located outside the European Union (in the same country as the data importer or in another third country, hereinafter "onward transfer") if the third party is or agrees to be bound by these Clauses, under the appropriate Module, or if:

·(i) the onward transfer is to a country benefiting from an adequacy decision pursuant to Article 45 of Regulation (EU) 2016/679 that covers the onward transfer;

·(ii) the third party otherwise ensures appropriate safeguards pursuant to Articles 46 or 47 Regulation of (EU) 2016/679 with respect to the processing in question;

·(iii) the onward transfer is necessary for the establishment, exercise or defence of legal claims in the context of specific administrative, regulatory or judicial proceedings; or

·(iv) the onward transfer is necessary in order to protect the vital interests of the data subject or of another natural person.

·Any onward transfer is subject to compliance by the data importer with all the other safeguards under these Clauses, in particular purpose limitation. 8.9 Documentation and compliance

·(a) The data importer shall promptly and adequately deal with enquiries from the data exporter that relate to the processing under these Clauses.

·(b) The Parties shall be able to demonstrate compliance with these Clauses. In particular, the data importer shall keep appropriate documentation on the processing activities carried out on behalf of the data exporter.

·(c) The data importer shall make available to the data exporter all information necessary to demonstrate compliance with the obligations set out in these Clauses and at the data exporter's request, allow for and contribute to audits of the processing activities covered by these Clauses, at reasonable intervals or if there are indications of non-compliance. In deciding on a review or audit, the data exporter may take into account relevant certifications held by the data importer.

·(d) The data exporter may choose to conduct the audit by itself or mandate an independent auditor. Audits may include inspections at the premises or physical facilities of the data importer and shall, where appropriate, be carried out with reasonable notice.

·(e) The Parties shall make the information referred to in paragraphs (b) and (c), including the results of any audits, available to the competent supervisory authority on request. Clause 9 Use of sub-processors

·(a) The data importer has the data exporter's general authorisation for the engagement of sub-processor(s) from an agreed list. The data importer shall specifically inform the data exporter in writing of any intended changes to that list through the addition or replacement of sub-processors at least 30 business days in advance, thereby giving the data exporter sufficient time to be able to object to such changes prior to the engagement of the sub-processor(s). The data importer shall provide the data exporter with the information necessary to enable the data exporter to exercise its right to object.

·(b) Where the data importer engages a sub-processor to carry out specific processing activities (on behalf of the data exporter), it shall do so by way of a written contract that provides for, in substance, the same data protection obligations as those binding the data importer under these Clauses, including in terms of third-party beneficiary rights for data subjects. The Parties agree that, by complying with this Clause, the data importer fulfils its obligations under Clause 8.8. The data importer shall ensure that the sub-processor complies with the obligations to which the data importer is subject pursuant to these Clauses.

·(c) The data importer shall provide, at the data exporter's request, a copy of such a sub-processor agreement and any subsequent amendments to the data exporter. To the extent necessary to protect business secrets or other confidential information, including personal data, the data importer may redact the text of the agreement prior to sharing a copy.

·(d) The data importer shall remain fully responsible to the data exporter for the performance of the sub-processor's obligations under its contract with the data importer. The data importer shall notify the data exporter of any failure by the sub-processor to fulfil its obligations under that contract.

·(e) The data importer shall agree a third-party beneficiary clause with the sub-processor whereby - in the event the data importer has factually disappeared, ceased to exist in law or has become insolvent - the data exporter shall have the right to terminate the sub-processor contract and to instruct the sub-processor to erase or return the personal data. Clause 10 Data subject rights

·(a) The data importer shall promptly notify the data exporter of any request it has received from a data subject. It shall not respond to that request itself unless it has been authorised to do so by the data exporter.

·(b) The data importer shall assist the data exporter in fulfilling its obligations to respond to data subjects' requests for the exercise of their rights under Regulation (EU) 2016/679. In this regard, the Parties shall set out in Annex II the appropriate technical and organisational measures, taking into account the nature of the processing, by which the assistance shall be provided, as well as the scope and the extent of the assistance required.

·(c) In fulfilling its obligations under paragraphs (a) and (b), the data importer shall comply with the instructions from the data exporter. Clause 11 Redress

·(a) The data importer shall inform data subjects in a transparent and easily accessible format, through individual notice or on its website, of a contact point authorised to handle complaints. It shall deal promptly with any complaints it receives from a data subject.

·(b) In case of a dispute between a data subject and one of the Parties as regards compliance with these Clauses, that Party shall use its best efforts to resolve the issue amicably in a timely fashion. The Parties shall keep each other informed about such disputes and, where appropriate, cooperate in resolving them.

·(c) Where the data subject invokes a third-party beneficiary right pursuant to Clause 3, the data importer shall accept the decision of the data subject to:

·(i) lodge a complaint with the supervisory authority in the Member State of his/her habitual residence or place of work, or the competent supervisory authority pursuant to Clause 13;

·(ii) refer the dispute to the competent courts within the meaning of Clause 18.

·(d) The Parties accept that the data subject may be represented by a not-for-profit body, organisation or association under the conditions set out in Article 80(1) of Regulation (EU) 2016/679.

·(e) The data importer shall abide by a decision that is binding under the applicable EU or Member State law.

·(f) The data importer agrees that the choice made by the data subject will not prejudice his/her substantive and procedural rights to seek remedies in accordance with applicable laws. Clause 12 Liability

·(a) Each Party shall be liable to the other Party/ies for any damages it causes the other Party/ies by any breach of these Clauses.

·(b) The data importer shall be liable to the data subject, and the data subject shall be entitled to receive compensation, for any material or non-material damages the data importer or its sub-processor causes the data subject by breaching the third-party beneficiary rights under these Clauses.

·(c) Notwithstanding paragraph (b), the data exporter shall be liable to the data subject, and the data subject shall be entitled to receive compensation, for any material or non-material damages the data exporter or the data importer (or its sub-processor) causes the data subject by breaching the third-party beneficiary rights under these Clauses. This is without prejudice to the liability of the data exporter and, where the data exporter is a processor acting on behalf of a controller, to the liability of the controller under Regulation (EU) 2016/679 or Regulation (EU) 2018/1725, as applicable.

·(d) The Parties agree that if the data exporter is held liable under paragraph (c) for damages caused by the data importer (or its sub-processor), it shall be entitled to claim back from the data importer that part of the compensation corresponding to the data importer's responsibility for the damage.

·(e) Where more than one Party is responsible for any damage caused to the data subject as a result of a breach of these Clauses, all responsible Parties shall be jointly and severally liable and the data subject is entitled to bring an action in court against any of these Parties.

·(f) The Parties agree that if one Party is held liable under paragraph (e), it shall be entitled to claim back from the other Party/ies that part of the compensation corresponding to its / their responsibility for the damage.

·(g) The data importer may not invoke the conduct of a sub-processor to avoid its own liability. Clause 13 Supervision

·(a) The supervisory authority with responsibility for ensuring compliance by the data exporter with Regulation (EU) 2016/679 as regards the data transfer, as indicated in Annex I.C, shall act as competent supervisory authority.

·(b) The data importer agrees to submit itself to the jurisdiction of and cooperate with the competent supervisory authority in any procedures aimed at ensuring compliance with these Clauses. In particular, the data importer agrees to respond to enquiries, submit to audits and comply with the measures adopted by the supervisory authority, including remedial and compensatory measures. It shall provide the supervisory authority with written confirmation that the necessary actions have been taken.

·SECTION III - LOCAL LAWS AND OBLIGATIONS IN CASE OF ACCESS BY PUBLIC AUTHORITIES

14Clause 14

·Local laws and practices affecting compliance with the Clauses

·(a) The Parties warrant that they have no reason to believe that the laws and practices in the third country of destination applicable to the processing of the personal data by the data importer, including any requirements to disclose personal data or measures authorising access by public authorities, prevent the data importer from fulfilling its obligations under these Clauses. This is based on the understanding that laws and practices that respect the essence of the fundamental rights and freedoms and do not exceed what is necessary and proportionate in a democratic society to safeguard one of the objectives listed in Article 23(1) of Regulation (EU) 2016/679, are not in contradiction with these Clauses.

·(b) The Parties declare that in providing the warranty in paragraph (a), they have taken due account in particular of the following elements:

·(i) the specific circumstances of the transfer, including the length of the processing chain, the number of actors involved and the transmission channels used; intended onward transfers; the type of recipient; the purpose of processing; the categories and format of the transferred personal data; the economic sector in which the transfer occurs; the storage location of the data transferred;

·(ii) the laws and practices of the third country of destination- including those requiring the disclosure of data to public authorities or authorising access by such authorities - relevant in light of the specific circumstances of the transfer, and the applicable limitations and safeguards;

·(iii) any relevant contractual, technical or organisational safeguards put in place to supplement the safeguards under these Clauses, including measures applied during transmission and to the processing of the personal data in the country of destination.

·(c) The data importer warrants that, in carrying out the assessment under paragraph (b), it has made its best efforts to provide the data exporter with relevant information and agrees that it will continue to cooperate with the data exporter in ensuring compliance with these Clauses.

·(d) The Parties agree to document the assessment under paragraph (b) and make it available to the competent supervisory authority on request.

·(e) The data importer agrees to notify the data exporter promptly if, after having agreed to these Clauses and for the duration of the contract, it has reason to believe that it is or has become subject to laws or practices not in line with the requirements under paragraph (a), including following a change in the laws of the third country or a measure (such as a disclosure request) indicating an application of such laws in practice that is not in line with the requirements in paragraph (a).

·(f) Following a notification pursuant to paragraph (e), or if the data exporter otherwise has reason to believe that the data importer can no longer fulfil its obligations under these Clauses, the data exporter shall promptly identify appropriate measures (e.g. technical or organisational measures to ensure security and confidentiality) to be adopted by the data exporter and/or data importer to address the situation. The data exporter shall suspend the data transfer if it considers that no appropriate safeguards for such transfer can be ensured, or if instructed by the competent supervisory authority to do so. In this case, the data exporter shall be entitled to terminate the contract, insofar as it concerns the processing of personal data under these Clauses. If the contract involves more than two Parties, the data exporter may exercise this right to termination only with respect to the relevant Party, unless the Parties have agreed otherwise. Where the contract is terminated pursuant to this Clause, Clause 16(d) and (e) shall apply. Clause 15

·Obligations of the data importer in case of access by public authorities 15.1 Notification

·(a) The data importer agrees to notify the data exporter and, where possible, the data subject promptly (if necessary with the help of the data exporter) if it:

·(i) receives a legally binding request from a public authority, including judicial authorities, under the laws of the country of destination for the disclosure of personal data transferred pursuant to these Clauses; such notification shall include information about the personal data requested, the requesting authority, the legal basis for the request and the response provided; or

·(ii) becomes aware of any direct access by public authorities to personal data transferred pursuant to these Clauses in accordance with the laws of the country of destination; such notification shall include all information available to the importer.

·(b) If the data importer is prohibited from notifying the data exporter and/or the data subject under the laws of the country of destination, the data importer agrees to use its best efforts to obtain a waiver of the prohibition, with a view to communicating as much information as possible, as soon as possible. The data importer agrees to document its best efforts in order to be able to demonstrate them on request of the data exporter.

·(c) Where permissible under the laws of the country of destination, the data importer agrees to provide the data exporter, at regular intervals for the duration of the contract, with as much relevant information as possible on the requests received (in particular, number of requests, type of data requested, requesting authorities, whether requests have been challenged and the outcome of such challenges, etc.).

·(d) The data importer agrees to preserve the information pursuant to paragraphs (a) to (c) for the duration of the contract and make it available to the competent supervisory authority on request.

·(e) Paragraphs (a) to (c) are without prejudice to the obligation of the data importer pursuant to Clause 14(e) and Clause 16 to inform the data exporter promptly where it is unable to comply with these Clauses.

15.215.2 Review of legality and data minimisation

·(a) The data importer agrees to review the legality of the request for disclosure, in particular whether it remains within the powers granted to the requesting public authority, and to challenge the request if, after careful assessment, it concludes that there are reasonable grounds to consider that the request is unlawful under the laws of the country of destination, applicable obligations under international law and principles of international comity. The data importer shall, under the same conditions, pursue possibilities of appeal. When challenging a request, the data importer shall seek interim measures with a view to suspending the effects of the request until the competent judicial authority has decided on its merits. It shall not disclose the personal data requested until required to do so under the applicable procedural rules. These requirements are without prejudice to the obligations of the data importer under Clause 14(e).

·(b) The data importer agrees to document its legal assessment and any challenge to the request for disclosure and, to the extent permissible under the laws of the country of destination, make the documentation available to the data exporter. It shall also make it available to the competent supervisory authority on request.

·(c) The data importer agrees to provide the minimum amount of information permissible when responding to a request for disclosure, based on a reasonable interpretation of the request.

·SECTION IV - FINAL PROVISIONS

16Clause 16

·Non-compliance with the Clauses and termination

·(a) The data importer shall promptly inform the data exporter if it is unable to comply with these Clauses, for whatever reason.

·(b) In the event that the data importer is in breach of these Clauses or unable to comply with these Clauses, the data exporter shall suspend the transfer of personal data to the data importer until compliance is again ensured or the contract is terminated. This is without prejudice to Clause 14(f).

·(c) The data exporter shall be entitled to terminate the contract, insofar as it concerns the processing of personal data under these Clauses, where:

·(i) the data exporter has suspended the transfer of personal data to the data importer pursuant to paragraph (b) and compliance with these Clauses is not restored within a reasonable time and in any event within one month of suspension;

·(ii) the data importer is in substantial or persistent breach of these Clauses; or

·(iii) the data importer fails to comply with a binding decision of a competent court or supervisory authority regarding its obligations under these Clauses.

·In these cases, it shall inform the competent supervisory authority of such non-compliance. Where the contract involves more than two Parties, the data exporter may exercise this right to termination only with respect to the relevant Party, unless the Parties have agreed otherwise.

·(d) Personal data that has been transferred prior to the termination of the contract pursuant to paragraph (c) shall at the choice of the data exporter immediately be returned to the data exporter or deleted in its entirety. The same shall apply to any copies of the data. The data importer shall certify the deletion of the data to the data exporter. Until the data is deleted or returned, the data importer shall continue to ensure compliance with these Clauses. In case of local laws applicable to the data importer that prohibit the return or deletion of the transferred personal data, the data importer warrants that it will continue to ensure compliance with these Clauses and will only process the data to the extent and for as long as required under that local law.

·(e) Either Party may revoke its agreement to be bound by these Clauses where (i) the European Commission adopts a decision pursuant to Article 45(3) of Regulation (EU) 2016/679 that covers the transfer of personal data to which these Clauses apply; or (ii) Regulation (EU) 2016/679 becomes part of the legal framework of the country to which the personal data is transferred. This is without prejudice to other obligations applying to the processing in question under Regulation (EU) 2016/679. Clause 17 Governing law

·These Clauses shall be governed by the law of one of the EU Member States, provided such law allows for third-party beneficiary rights. The Parties agree that these Clauses shall be governed in accordance with the 'Contracting Entity; Applicable Law; Notice' section of the Jurisdiction Specific Terms or if such section does not specify an EU Member State, by the law of the Republic of Ireland (without reference to conflicts of law principles) Clause 18 Choice of forum and jurisdiction

·(a) Any dispute arising from these Clauses shall be resolved by the courts of an EU Member State.

·(b) The Parties agree that those shall be the courts of the jurisdiction specified in Clause 17.

·(c) A data subject may also bring legal proceedings against the data exporter and/or data importer before the courts of the Member State in which he/she has his/her habitual residence.

·(d) The Parties agree to submit themselves to the jurisdiction of such courts.

·UK AND SWISS ADDENDUM TO THE STANDARD CONTRACTUAL CLAUSES

·(a) This Addendum amends the Standard Contractual Clauses to the extent necessary so they operate for transfers made by the data exporter to the data importer, to the extent that the UK GDPR or Swiss DPA (as defined in this Data Processing Agreement) apply to the data exporter's processing when making that transfer.

·(b) The Standard Contractual Clauses shall be amended with the following modifications:

·(i) references to "Regulation (EU) 2016/679" shall be interpreted as references to the UK GDPR or Swiss DPA (as applicable);

·(ii) references to specific Articles of "Regulation (EU) 2016/679" shall be replaced with the equivalent article or section of the UK GDPR or Swiss DPA (as applicable);

·(iii) references to Regulation (EU) 2018/1725 shall be removed;

·(iv) references to "EU", "Union" and "Member State" shall be replaced with references to the "UK" or "Switzerland" (as applicable);

·(v) Clause 13(a) and Part C of Annex II are not used and the "competent supervisory authority" shall be the United Kingdom Information Commissioner or Swiss Federal Data Protection Information Commissioner (as applicable);

·(vi) references to the "competent supervisory authority" and "competent courts" shall be replaced with references to the "Information Commissioner" and the "courts of England and Wales" or the "Swiss Federal Data Protection Information Commissioner" and "applicable courts of Switzerland" (as applicable);

·(vii) in Clause 17, the Standard Contractual Clauses shall be governed by the laws of England and Wales or Switzerland (as applicable); and

·(viii) to the extent the UK GDPR applies to the processing, Clause 18 shall be replaced to state: "Any dispute arising from these Clauses shall be resolved by the courts of England and Wales. A data subject may also bring legal proceedings against the data exporter and/or data importer before the courts of any country in the UK. The Parties agree to submit themselves to the jurisdiction of such courts"; and

·(ix) to the extent the Swiss DPA applies to the processing, Clause 18 shall be replaced to state: "Any dispute arising from these Clauses shall be resolved by the competent courts of Switzerland. The Parties agree to submit themselves to the jurisdiction of such courts".

1Password Partner Agreement · Data Processing Agreement | SaaS Manager — 1Password