Data Processing Addendum
This Data Processing Addendum (this “DPA” or “Addendum”) is entered into by and between RevolutionParts, Inc., a Delaware corporation (the “Processor”) and the individual or entity identified as the Customer and bound by its signatory (the “Customer”) to the Master SaaS Agreement or the Terms of Service, as applicable, between the Parties (the “Agreement”), into which this Addendum is incorporated in full.
In consideration of the mutual covenants and agreements between the Parties, and for other good and valuable consideration, the receipt and sufficiency of which are hereby acknowledged, the Processor and the Customer (each a “Party” or collectively the “Parties”) agree as follows.
- DEFINITIONS.
Unless otherwise indicated, all capitalized terms used but not defined in this DPA have the meanings given to them in Regulation (EU) 2016/679, the General Data Protection Regulation (“GDPR”), the California Consumer Privacy Act, Cal. Civ. Code § 1798.100 et seq. (“CCPA”) or other applicable data privacy or protection law.
For the purposes of this DPA, the following definitions shall apply:
- “Applicable Law” means applicable data privacy law, which may include, as such laws are promulgated and amended from time to time: the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and its national implementations in the European Economic Area (“EEA”); the Personal Protection and Electronic Documents Act (“PIPEDA”); the California Consumer Privacy Act, as amended (“CCPA”); the Colorado Privacy Act; the Connecticut Personal Data Privacy and Online Monitoring Act; the Delaware Personal Data Privacy Act; the Florida Digital Bill of Rights; the Indiana Consumer Data Protection Act; the Iowa Consumer Data Protection Act; the Kentucky Consumer Data Protection Act; the Maryland Online Data Privacy Act; the Montana Consumer Data Privacy Act; the New Hampshire Data Privacy Act; the New Jersey Data Privacy Act; the Oregon Consumer Data Privacy Act; the Tennessee Information Privacy Act; the Texas Data Privacy and Security Act; the Utah Consumer Privacy Act; and the Virginia Consumer Data Privacy Act. For the avoidance of doubt, to the extent Processor processes Personal Data not governed by, or Processor’s processing activities are not governed by, any Applicable Law, such law is not applicable for purposes of this DPA. Each Party is only responsible for complying with the Applicable Law applicable to it.
- “Controller” means a person or entity that alone, or jointly with others, determines the purposes and means of Processing the Personal Data. Where applicable, Controller shall be interpreted consistent with the same or similar term under Applicable Law. Customer is the Controller for purposes of this DPA.
- “Data Subject” shall have the meaning ascribed to it under Applicable Law, or, otherwise shall mean a natural person to which Personal Data pertains.
- “Personal Data” shall include “personal data,” “personal information,” and “personally identifiable information,” and such terms shall have the same meaning as defined by Applicable Law.
- “Personal Data Breach” means the accidental or unlawful destruction, loss, alteration, unauthorized disclosure or exfiltration of, or access to Personal Data.
- “Process” and “Processing” mean any operation or set of operations performed on Personal Data or sets of Personal Data, including, but not limited to, by automated means, such as collecting, recording, organizing, creating, structuring, storing, adapting, altering, manipulating, copying, retrieving, backing up, analyzing, deriving, extracting, consulting, using, disclosing by transmission, disseminating, or otherwise making available, aligning or combining, restricting, erasing, destroying, and, where applicable, shall be interpreted consistent with the same or similar term under Applicable Law.
- “Processor” means the entity that Processes Personal Data on behalf of the Data Controller, which may include, as applicable, a “Service Provider” as that term is defined under Applicable Law. Processor is the Processor for purposes of this DPA.
- “Standard Contractual Clauses” means the annex found in EU Commission Implementing Decision of 4 June 2021 on standard contractual clauses for the transfer of personal data to processors established in third countries under Directive 95/46/EC of the European Parliament, as amended or replaced from time to time.
- “Security Incident” (or “Data Breach”) shall have the meanings ascribed to them under Applicable Law, or the unauthorized access, use, disclosure, destruction, or alteration of Personal Data.
- “Sub-Processor” means any Processor affiliate or subcontractor engaged by Processor for the Processing of Personal Data, and where applicable shall be interpreted consistent with the same or similar term under Applicable Law.
- SCOPE, ROLES, AND PROCESSING OF PERSONAL DATA.
- Scope. This DPA applies only to Processor’s Processing of Customer Personal Data for the nature, purposes, and duration set forth herein and in the Agreement, including provision of the Services as set forth therein (the “Services”) (together, the “Purpose”).
- Customer as Controller. For purposes of this Agreement, Customer is the Controller, the Party responsible for determining the purposes and means for which Customer Personal Data is Processed, and Customer appoints Processor to Process the Customer Personal Data on behalf of Customer. The Agreement and this DPA constitute Customer’s complete and final instructions to Processor regarding the Processing of Personal Data, including for purposes of the Standard Contractual Clauses.
- Customer Obligations as Controller. Customer is solely responsible for and shall: (a) comply at all times with Applicable Law; (b) ensure the accuracy of its Personal Data shared with Processor and that the Personal Data is obtained lawfully; (c) not violate the rights of any third parties; and (d) not instruct Processor to Process Personal Data in violation of any Applicable Law or other agreements to which Customer may be bound.
- Processor’s Obligations as Processor of Personal Data. Processor shall (a) materially comply at all times with Applicable Law; (b) provide the level of privacy protection required by Applicable Law; (c) provide Customer with all commercially reasonable assistance to enable Customer to fulfill its own obligations or exercise its rights under Applicable Law; (d) restrict access to Personal Data to those authorized persons who need such information to provide the Services; (e) maintain the confidentiality of the Personal Data, and, (d) comply with this DPA.
- Restrictions on Processing. Except as expressly permitted by Applicable Law, Processor shall not: (a) sell or share the Customer Personal Data; (b) retain, use, or disclose the Customer Personal Data for any purpose other than the Purpose; (c) retain, use, or disclose the Customer Personal Data outside the direct business relationship with the Customer; or, (d) combine the Customer Personal Data with data or Personal Data that Processor receives from, or on behalf of, another person or persons, except to perform the Purpose.
- Sub-Processors. Processor may engage Sub-Processors to assist performing in the Purpose, which may involve Processing of Customer Personal Data. Processor will maintain a list of such Sub-Processors and make it available to Customer upon request. On reasonable grounds pertaining to compliance with or violation of Applicable Law, Customer may make an objection to the use of a Sub-Processer to Process its Personal Data. If a reasonable basis exists to conclude such Sub-Processor may not be able to adequately protect Personal Data in accordance with Applicable Law, Processor may use commercially reasonable efforts to consider whether a change in Processing, configuration, organization, management and use of its Sub-Processors, or other solution or remedy may mitigate or avoid the Processing of the Customer’s Personal Data by such Processor without unreasonably burdening Processor, Customer, and Processor’s other clients. Where Processor engages a Sub-Processor for carrying out specific Processing activities on behalf of Customer, Processor shall impose contractual obligations on the Sub-Processor that are substantially the same as those imposed on Processor under this DPA. Where a Sub-Processor fails to fulfill its data protection obligations, Processor will remain liable to Customer for the performance of such Sub-Processor’s obligations.
- DATA SUBJECT REQUESTS.
- Data Subject Requests. To the extent required by Applicable Law, Processor shall notify the Customer of any requests from Data Subjects (including, “verifiable consumer requests”) exercising their rights under Applicable Law, including (a) to access, or otherwise exercise their right to know, their Personal Data; (b) to have their Personal Data corrected or erased; (c) to object to Processor’s Processing of the Personal Data; or, (d) data portability requests (“Data Subject Requests”).
- Processor’s Assistance. Processor may provide appropriate, commercially reasonable assistance to Customer, including technical and organizational measures, insofar as possible, to assist Customer with meeting Customer’s obligations to respond to a Data Subject Request received by Customer. Customer’s failure to cooperate with Processor, or otherwise to comply with its obligations under Applicable Law, shall absolve Processor of any obligation or responsibility to provide or continue to provide such assistance and any liability arising therefrom. Processor shall cooperate to the extent reasonably necessary in connection with Customer’s requests related to any legally required data protection impact assessments and consultation with supervisory authorities.
- Third-Party Requests. If Processor receives a request from a third party in connection with any government investigation or court proceeding that Processor believes would require it to produce any Personal Data, Processor shall inform Customer in writing of such request and reasonably cooperate with Customer to limit, challenge, or protect against such disclosure, to the extent permitted by Applicable Law. Upon a request issued by a supervisory authority for records regarding Personal Data, Processor will cooperate to provide the supervisory authority with records pertaining to Processing activities performed on Customer’s behalf. To the extent legally permissible, Processor shall inform Customer in writing of such a request and provide commercially reasonable assistance to verify the legal basis of the request.
- Deletion or Return of Customer Personal Data. Where expressly permitted by Applicable Law, Processor shall not be required to delete any Customer Personal Data solely to comply with a Customer or Data Subject Request.
- SECURITY, CONTROLS, AND SAFEGUARDS.
- Processor Controls. Process shall use commercially reasonable security measures and safeguards to protect Customer Personal Data, including, but not necessarily limited to: (a) designating an authorized privacy administrator responsible for implementing and supervising security measures; (b) performing annual risk assessments to identify reasonably foreseeable external and internal risks that could result in the unauthorized disclosure, misuse, alternation, destruction, or other compromise of Customer Personal Data and to assess the sufficiency of any safeguards in place to control these risks; (c) ensuring that Processor personnel are trained in their responsibilities under Applicable Law; (d) implementing network and software systems to limit the risk of unauthorized access to Customer Personal Data, which includes, but is not necessarily limited to, designing limitations to access, maintaining appropriate screening programs to detect risks, and implementing security patches; (e) maintaining effective systems to prevent, detect, and respond to attacks, intrusions, and other system failures; (f) implementing monitoring systems to regularly test and monitor the effectiveness of Processor’s information security safeguards; and (g) such other cybersecurity controls, physical security measures, data encryption, vendor risk management, incident response planning, or risk management, business continuity, and disaster preparedness planning as Processor deems necessary or appropriate from time to time.
- Audits. Not more than once annually (unless otherwise required by Applicable Law), Processor shall allow for and contribute to audits, including inspections, conducted by Customer, or a third-party auditor chosen by Customer, to demonstrate Processor’ compliance with this DPA or Article 28 of the GDPR. For clarity, such audits and inspections are limited to Processor’s Processing of Personal Data subject to the GDPR on behalf of Customer only and not any other aspect of Processor’s business or information systems, nor other clients of Processor. If Customer requires Processor to contribute to audits or inspections that are lawful and necessary to demonstrate compliance, Customer shall provide Processor with written notice at least sixty (60) days in advance of such audit or inspection. Such written notice shall specify the information, data, and locations to be made available to the auditor or inspector. Such written notice, and anything produced in response to it (including any derivative work product such as notes of interviews), shall be considered Confidential Information and, notwithstanding anything to the contrary in this DPA, Agreement, or any other contract, agreement, or instructions, shall remain Confidential Information in perpetuity or for the maximum time period permitted by law. Such materials and derivative work product produced in response to Customer’s request shall not be disclosed to any third party without the prior written permission of Processor, unless such disclosure is required by Applicable Law, in which case Customer shall give Processor prompt written notice and an opportunity to obtain a protective order to prohibit or restrict such disclosure, except to the extent such notice is prohibited by Applicable Law, an order of a court, or a governmental agency. Customer shall make every effort to cooperate with Processor to schedule audits or inspections at times that are convenient to Processor. To the extent Customer uses a third-party representative to conduct the audit, Customer shall ensure that such third-party representative is bound by obligations of confidentiality no less protective than those contained in this DPA and the confidentiality provisions containing in the Agreement. If, after reviewing Processor’s response to Customer’s audit or inspection request, Customer requires additional inquiries, audits, or inspections, Customer acknowledges and agrees that it shall be solely responsible for all costs incurred in relation to such additional audits or inspections.
- SECURITY INCIDENT OR DATA BREACH.
- Processor Security Incident Obligations. To the extent required under Applicable Law, or otherwise to the extent commercially reasonable, Processor shall (a) notify Customer of any Security Incident or Data Breach, (b) assist Customer by providing information pertaining to the nature and details of the Security Incident or Data Breach to the extent known, which may include the nature of the data breach, the number and categories of data subjects and data records affected, and the name and contact details for the relevant contact person at Processor and, (c) if the Security Incident or Data Breach is the direct result of an act or omission of Processor, then (c)(i) remediate the cause, and/or (c)(ii) mitigate the damages, both the to the extent within Processor’s reasonable control. Processor’s obligations hereunder shall not apply to Security Incidents or Data Breaches that are caused, directly or indirectly, by the acts or omissions of Customer. Customer is solely responsible for complying with legal requirements for notification applicable to Customer and fulfilling any third-party notification obligations related to any Security Incident or Data Breach. Nothing herein shall be construed to require Processor to violate, or delay compliance with, any legal obligation it may have with respect to a Security Incident or Data Breach or other security incidents generally.
- DATA TRANSFER.
- Cross-Border Transfers. Customer authorizes Processor to transfer, store, or Process Personal Data in the United States or any other country in which Processor or its Sub-Processors maintain Processing facilities. Customer appoints Processor to perform any such transfer of Personal Data to any such country and to store and Process Personal Data for the Purpose. Processor shall conduct all such activity in compliance with the Agreement, this DPA, and Applicable Law.
- Data Transfers from the EU. To the extent that Personal Data originating from the EEA or Switzerland is transferred outside the EEA or Switzerland, the Processor shall ensure that such transfer is carried out in material compliance with Applicable Law, including the Standard Contractual Clauses. Where necessary, the Processor shall implement appropriate safeguards or other approved “data transfer mechanisms” to ensure an adequate level of protection for the Personal Data.
- Transfers from the United Kingdom. To the extent that Personal Data originating from the United Kingdom is transferred outside of the United Kingdom, for such transfer the Parties shall be bound by the UK International Transfer Addendum to the EU Commission’s Standard Contractual Clauses, as such laws are amended and replaced from time to time. If there is a conflict between the Standard Contractual Clauses and the Agreement, or this DPA, the Standard Contractual Clauses shall prevail.
- TERM AND TERMINATION.
- Term. To the extent applicable to the Agreement with Processor, this DPA shall share the same Effective Date and/or commencement date and shall also expire or terminate commensurately therewith.
- Obligations Upon Termination. Upon termination of the Agreement, Processor shall cease Processing and shall delete or destroy any Customer Personal Data in its or its subcontractors’ and Sub-Processors’ possession without undue delay, provided, however, that Processor may retain Customer Personal Data to the extent allowed or required by Applicable Law, to the extent and for such period as may be permitted or required thereby. Processor may anonymize or de-identify the Customer Personal Data to satisfy its obligations under this clause.
- DPA LIABILITY.
Notwithstanding anything to the contrary herein, or in the Agreement, and to the maximum extent permitted by Applicable Law, Processor’s total liability hereunder, in aggregate, for all claims arising out of or relating to this DPA, shall not exceed the policy limits of the insurance coverage carried by Processor that is actually in force during the relevant period. This limitation shall apply to all claims, whensoever or howsoever arising, all types and categories of damages, including but not limited to direct, indirect, special, incidental, and consequential damages, and shall apply regardless of the form or cause of action, whether in contract, tort (including negligence), or otherwise.
TO THE MAXIMUM EXTENT PERMITTED UNDER APPLICABLE LAW, PROCESSOR SHALL NOT BE LIABLE TO CUSTOMER OR TO ANY THIRD PARTY FOR ANY LOSS OF USE, REVENUE, OR PROFIT, OR LOSS OF DATA OR DIMINUTION IN VALUE, OR FOR ANY CONSEQUENTIAL, INCIDENTAL, STATUTORY, INDIRECT, EXEMPLARY, SPECIAL, OR PUNITIVE DAMAGES, WHETHER SUCH LIABILITY IS BASED IN OR ARISING OUT OF BREACH OF CONTRACT, TORT (INCLUDING NEGLIGENCE), STRICT LIABILITY, OR OTHERWISE, REGARDLESS OF WHETHER SUCH DAMAGE WAS FORESEEABLE AND WHETHER OR NOT CUSTOMER HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES, AND NOTWITHSTANDING THE FAILURE OF ANY AGREED OR OTHER REMEDY OF ITS ESSENTIAL PURPOSE.
EACH PROVISION OF THIS ADDENDUM, OR THE AGREEMENT, THAT PROVIDES FOR A LIMITATION OF LIABILITY, DISCLAIMER OF WARRANTIES, OR EXCLUSION OF DAMAGES IS INTENDED TO AND DOES ALLOCATE THE RISKS BETWEEN THE PARTIES AND IS AN ESSENTIAL ELEMENT OF THE BENEFIT OF THE BARGAIN BETWEEN THE PARTIES. EACH OF THESE PROVISIONS IS SEVERABLE AND INDEPENDENT OF ALL OTHER PROVISIONS OF THIS ADDENDUM.
APPENDIX I
SAFEGUARDS AND SECURITY MEASURES APPENDIX
This Safeguards and Security Measures Appendix (this “Appendix” or “Safeguards and Security Measures Appendix”) shall be incorporated into and governed by the Processor’s Data Processing Addendum (the “DPA”). Capitalized terms used but not defined in this Appendix shall have the meanings set forth in the DPA. Processor represents and warrants that, as of the effective date of this Appendix, it currently maintains in place the safeguards and security measures (the “Safeguards and Security Measures”) as set forth herein, provided that such safeguards and security measures may be updated, amended, substituted, or otherwise changed from time to time, in the sole discretion of Processor.
Effective Date of Appendix: March 31st, 2026.
| CATEGORY | ITEM | DESCRIPTION |
|---|---|---|
| Cybersecurity Controls | Role-based access control (RBAC) | Use of RBAC to restrict system access based on user roles, ensuring individuals only have access to the resources necessary for their responsibilities; Defined user roles with specific permissions. |
| Multi-factor authentication (MFA) | Users required to provide multiple forms of verification before accessing systems or data; Specific features may include SMS, authenticator apps, and/or biometics. | |
| Firewall, Antivirus, and Intrusion Prevention Systems | Maintenance of robust firewalls and antivirus systems to control network traffic, prevent unauthorized access, and protect against malware; Specific features may include deep packet inspection, application-layer filtering, and threat intelligence integration. | |
| Next-Generation Firewalls (NGFW) | Next-Generation Firewalls (NGFW) provide intrusion detection and prevention, application-layer filtering, and deep packet inspection. | |
| Application Layer Firewalls | Firewalls that operate at the application layer to monitor and control communication between applications, enhancing security against application-specific attacks; Inspect and filter traffic. | |
| Segregate Sensitive Data Networks | Network segmentation to segregate sensitive data from other parts of the network, limiting potential exposure in the event of a breach. | |
| VLANs (Virtual Local Area Networks) | Use of VLANs to create virtual segmentation within a physical network, isolating different groups of devices and reducing the scope of potential attacks. | |
| Regular Security Audits and Vulnerability Assessments | Periodic security audits and vulnerability assessments to identify and address weaknesses in systems, networks, and applications, enhancing overall security posture. | |
| Identity and Access Management (IAM) | Use of IAM policies to manage user identities and control access to systems, applications, and data based on roles and responsibilities, which may include user provisioning, deprovisioning, role-based access controls, and regular access reviews. Implement multi-factor authentication for enhanced security. | |
| Privileged Access Management (PAM) | Use of PAM solutions to secure and manage privileged accounts, ensuring that only authorized personnel have access to critical systems and sensitive data, which may include just-in-time access, session recording, and automated credential rotation through PAM tools. | |
| Security Information and Event Management (SIEM) Systems | Implementation of SIEM systems to monitor and analyze security events in real-time, enabling rapid detection and response to potential security incidents; Configuration of correlation rules to detect abnormal patterns and trigger alerts for immediate response; Periodic review of SIEM logs for anomalies and fine-tune configurations. | |
| Regular Data Backups | Regular data backup processes to ensure the availability and integrity of critical data in the event of data loss or system failures, may include storage in secure and geographically diverse locations. | |
| Real-time Data Monitoring | Real-time monitoring tools to detect and respond to anomalous activities, unauthorized access, and potential security incidents | |
| Security Audits | Security audits assess the effectiveness of security controls, policies, and procedure. | |
| Data Protection and Privacy | Data Classification Policy | Classification of data into categories such as public, internal, confidential, and restricted; Encryption and access controls based on data classification. |
| Data Privacy Impact Assessments (DPIAs) | Periodic DPIAs to assess the privacy implications of data processing activities and ensure compliance with privacy regulations. | |
| Data Minimization | Collection and retention of only necessary data; Deletion of unused/unnecessary customer data; Secure data destruction methods, including overwriting and/or degaussing before disposal. | |
| Secure Data Destruction Policies | Secure destruction of data, including overwriting and/or degaussing before disposal of storage media. | |
| Data Erasure Tools | Use of reputable data erasure tools to ensure the effective and secure removal of data from storage devices, preventing unauthorized recovery, and ensuring compliance with recognized standards. | |
| Physical Security Measures | Access Controls for Physical Facilities | Access control systems and surveillance cameras at physical facilities to prevent unauthorized physical access to sensitive areas. |
| Environmental Controls (e.g., Climate Controls, Fire Suppression) | Climate control systems to maintain optimal temperature and humidity levels; Fire suppression systems like sprinklers and fire extinguishers; Regular maintenance checks. | |
| Encryption of Sensitive Data | Implementation of Data Encryption Technologies | Use of industry-standard encryption algorithms (e.g., AES) for data at rest. SSL/TLS protocols for secure data transmission. |
| Encryption Policies and Controls | Encryption policies specifying controls and procedures for the proper implementation and use of encryption throughout the organization. | |
| Strong Encryption Algorithms | Strong encryption algorithms such as AES (Advanced Encryption Standard) for data at rest and in transit to enhance data protection; AES-256 for data at rest and utilize TLS 1.3 for secure data transmission over networks. | |
| End-to-End Encryption | End-to-end encryption to protect data throughout its entire lifecycle, ensuring that only authorized parties can access the plaintext. | |
| Vendor Risk Management | Vendor Security Assessments | Use of a standardized security assessment questionnaire for vendors. Regular review and updating of the questionnaire based on evolving security standards. |
| Contractual Agreements with Security Provisions | Use of contracts that clearly define security requirements, including data protection, incident response, and periodic security audits in vendor contracts. | |
| Incident Response Planning | Development and Testing of Incident Response Plans | An incident response plan outlines procedures for detecting, responding to, and recovering from cybersecurity incidents. Periodic drills test the effectiveness of these plans. |
| Post-Incident Review and Improvement | A post-incident review team analyzes any incident thoroughly to identify root causes and implement corrective actions to enhance incident response capabilities. | |
| Employee Training and Awareness | Regular Security Training Programs | Regular training covering topics such as password hygiene, social engineering awareness, and safe web browsing. Periodic updates based on emerging threats. |
| Phishing Simulation Exercises | Periodic phishing simulation exercises to train employees in recognizing and avoiding phishing attempts, may include use of tools like or similar to KnowBe4 or PhishMe to simulate phishing attacks. Feedback and additional training to employees who fall for simulated phishing attempts. | |
| Financial Risk Management, Business Continuity, Disaster Preparation and Recovery | Cyber Liability Insurance | Maintenance of cyber liability insurance policy for financial protection against costs associated with cybersecurity incidents, including legal expenses, notifications, and regulatory fines. |
| Business Continuity Plan | A business continuity plan ensuring Company’s ability to maintain essential operations during cyber-related disruptions or disasters. | |
| Incident Cost Estimation, Financial Contingency Plan | An estimate of potential financial losses associated with different types of cybersecurity incidents; Financial contingency plan that outlines how the organization will manage unexpected financial impacts resulting from cybersecurity incidents, ensuring financial stability during crises; Emergency fund for immediate incident response costs, such as hiring cybersecurity experts, legal assistance, and communication efforts | |
| Business Interruption Insurance | Maintenance of business interruption insurance for income loss and additional expenses during periods of disruption caused by cybersecurity incidents. |