These International Transfer Terms are Schedule 3 to the Revup Data Processing Addendum (“DPA”). They provide the contractual safeguards used when Customer Personal Data is transferred from the European Economic Area (“EEA”), United Kingdom, or Switzerland to Revup Inc in the United States and the transfer is not otherwise covered by an applicable adequacy decision or adequacy regulation.
These terms do not create a separate agreement. They form part of the DPA whenever the DPA applies. Capitalized terms have the meanings given in the DPA.
1. Parties and transfer roles
Data exporter: The Customer identified in the agreement governing Customer's use of Revup. Customer is a Controller or Processor, as applicable.
Data importer: Revup Inc, 320 Boston Post Rd, Suite 180, #1070, Darien, Connecticut 06820, United States. Revup is a Processor or Subprocessor, as applicable. Privacy contact: [email protected].
The categories of Data Subjects, types of Customer Personal Data, purposes, duration, security measures, and Subprocessors are described in Schedules 1 and 2 of the DPA and at https://revup.com/subprocessors/.
2. EEA transfers
For a Restricted Transfer from the EEA, the parties incorporate the standard contractual clauses in the Annex to European Commission Implementing Decision (EU) 2021/914 (“SCCs”). The official SCC text is available at:
https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj
The SCCs are completed as follows:
- Customer is the data exporter and Revup is the data importer.
- Module Two applies when Customer is a Controller and Revup is a Processor.
- Module Three applies when Customer is a Processor and Revup is a Subprocessor.
- The optional docking clause in Clause 7 does not apply.
- Clause 9 uses Option 2, general written authorization. Revup will provide the Subprocessor notice stated in the DPA, currently at least 30 days before a new or replacement material Subprocessor begins Processing Customer Personal Data, except for a reasonably necessary emergency replacement.
- The optional language in Clause 11 does not apply.
- Clause 17 uses Option 1 and the SCCs are governed by Irish law.
- Under Clause 18, disputes will be resolved by the courts of Ireland.
- SCC Annex I.A and Annex I.B are populated by Schedule 1 of the DPA.
- SCC Annex I.C is populated under Section 5 below.
- SCC Annex II is populated by Schedule 2 of the DPA.
- SCC Annex III does not apply because Clause 9 uses general written authorization. Revup's Subprocessor List remains the operative list of current Subprocessors.
By entering the Customer agreement, each party is deemed to have signed the SCCs and their Annex I signature block. Revup will provide a separately signed copy when reasonably requested to demonstrate compliance.
3. United Kingdom transfers
For a Restricted Transfer from the United Kingdom, the SCCs apply as modified by the Approved Addendum's mandatory Part 2, which the parties incorporate by reference. This refers to ICO template B.1.0 submitted under section 119A of the Data Protection Act 2018, including revisions made under its Section 18. The ICO's current guidance and official downloads are available at:
The UK Addendum is completed as follows:
- Table 1 — Parties: Customer is the exporter and Revup is the importer, with the party details above and in Schedule 1 of the DPA.
- Table 2 — SCCs and modules: Module Two applies to Controller-to-Processor transfers and Module Three applies to Processor-to-Processor transfers, with the selections in Section 2 above.
- Table 3 — Appendix information: Schedule 1 of the DPA supplies Annex 1A and Annex 1B, and Schedule 2 supplies Annex II. Annex III does not apply because the parties selected general written authorization; Revup's Subprocessor List remains the operative list of current Subprocessors.
- Table 4 — Ending the Addendum if the Approved Addendum changes: the importer may end the UK Addendum as permitted by Section 19 of its mandatory clauses.
By entering the Customer agreement, each party agrees to be bound by the UK Addendum. The mandatory UK Addendum clauses control over the DPA and Customer agreement for a conflict concerning a UK Restricted Transfer.
4. Swiss transfers
For a Restricted Transfer from Switzerland, the SCCs apply with the following adaptations to the extent necessary under the Swiss Federal Act on Data Protection (“FADP”):
- references to the EU GDPR are interpreted to include the FADP;
- references to the European Union, EU, and Member States are interpreted to include Switzerland;
- the competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner;
- “personal data” includes personal data protected by the FADP;
- references to EU or Member State law are interpreted to include applicable Swiss law; and
- nothing limits a Data Subject's right under the SCCs to bring proceedings in Switzerland where the FADP permits.
Module Two applies when Customer is a Controller and Module Three applies when Customer is a Processor. For a transfer governed only by the FADP, Clause 17 is governed by Swiss law and disputes under Clause 18 may be brought before the competent courts of Switzerland. If the transfer is also governed by the EU GDPR, the EEA selections above apply without limiting rights available under the FADP. The remaining SCC selections and annex information described above apply to Swiss Restricted Transfers to the extent compatible with the FADP.
5. Competent supervisory authority
For an EEA Restricted Transfer, the competent supervisory authority under SCC Annex I.C is:
- the authority for the EEA member state where Customer is established;
- if Customer is not established in the EEA but has an Article 27 representative, the authority where that representative is established; or
- if Customer is not established in the EEA and has no Article 27 representative, an authority in an EEA member state where affected Data Subjects are located, as Customer identifies to Revup in writing.
For a UK Restricted Transfer, the competent authority is the United Kingdom Information Commissioner's Office. For a Swiss Restricted Transfer, it is the Swiss Federal Data Protection and Information Commissioner.
6. Transfer assessments and supplementary measures
The parties will comply with SCC Clause 14 and assess whether destination-country laws and practices prevent Revup from fulfilling the applicable transfer terms. The assessment will consider the circumstances of the transfer and relevant contractual, technical, and organizational safeguards.
Revup will provide information reasonably necessary for Customer to complete a transfer impact assessment or United Kingdom data-protection test, subject to confidentiality, security, and legal restrictions. If supplementary measures are reasonably necessary, the parties will cooperate in good faith to implement appropriate measures.
7. Government requests
Unless prohibited by law, Revup will notify Customer of a legally binding public-authority request for Customer Personal Data. Revup will review each request, challenge or seek to narrow a request where there are reasonable grounds to do so, and disclose only the information it is legally required to disclose. Revup will comply with the applicable SCC obligations concerning government access, documentation, and suspension of transfers.
8. Onward transfers
Revup may make an onward Restricted Transfer to an authorized Subprocessor only as permitted by the applicable SCC module, UK Addendum, FADP, and DPA. Revup will impose binding data-protection and transfer obligations on the Subprocessor as required by applicable law.
9. Alternative mechanisms
If a valid adequacy decision, adequacy regulation, Data Privacy Framework certification, or replacement transfer mechanism covers a transfer, the parties may rely on it. Revup does not claim Data Privacy Framework certification unless its active certification is publicly confirmed on the U.S. Department of Commerce Data Privacy Framework List.
If an applicable mechanism ceases to cover a transfer, the SCCs, UK Addendum, or another valid mechanism will apply as necessary without requiring a new signature, to the extent legally permitted.
10. Priority
The SCCs and mandatory UK Addendum clauses control over these terms, the DPA, and the Customer agreement for any conflict concerning a Restricted Transfer. Otherwise, the DPA and Customer agreement remain in effect.
Contact
Questions about these terms may be sent to [email protected].