Data Processing Addendum

Last updated: September 1, 2026

This Data Processing Addendum (“DPA”) forms a part of the Customer Agreement or if you (“Customer”) have entered into a separate agreement with Twingate Inc. (“Twingate”), then it forms a part of such written agreement, if incorporated by reference in such agreement (in either case, the “Agreement”).

By executing an Agreement that explicitly states that this DPA is incorporated by reference, Customer enters into this DPA on behalf of itself and, to the extent required under Applicable Data Protection Laws, in the name and on behalf of any of its affiliates who are authorized to use the Services.

If you are entering into this DPA on behalf of a company or other legal entity, you represent and warrant that you have the authority to bind that legal entity to this DPA. In that case, “Customer” will refer to that company or other legal entity.


PART A: DEFINITIONS & INTERPRETATION

1. Definitions

1.1. Definitions. In this DPA:

Applicable Data Protection Laws” has the meaning given to that term in the Agreement.

Applicable U.S. Privacy Laws” means the CCPA, the Virginia Consumer Data Protection Act, the Colorado Privacy Act, the Utah Consumer Privacy Act, the Connecticut Data Privacy Act, and any other U.S. state or federal laws governing personal data contained in the Customer Data.

CCPA” means the California Consumer Privacy Act of 2018, as amended, or any successor legislation.

Data Privacy Framework” or “DPF” means the EU-U.S. Data Privacy Framework (“EU-US DPF”), the UK Extension to the EU-U.S. DPF (“UK-US Extension”), and the Swiss-U.S. Data Privacy Framework (“Swiss-US DPF”) as set forth by the U.S. Department of Commerce.

Europe” means the European Economic Area (“EEA”), Switzerland, and the United Kingdom.

European Data Protection Law” means: (a) Regulation 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the Processing of Personal Data and on the free movement of such data (General Data Protection Regulation) (the "EU GDPR"); (b) the EU e-Privacy Directive (Directive 2002/58/EC); (c) the EU GDPR as saved into United Kingdom law by virtue of section 3 of the United Kingdom's European Union (Withdrawal) Act 2018 (the "UK GDPR"); (d) the Swiss Federal Act on Data Protection of 25 September 2020 and its corresponding ordinances ("Swiss FDPA"); and (e) any and all applicable national data protection laws made under, pursuant to or that apply in conjunction with any of (a), (b) or (c); in each case as may be amended or superseded from time to time.

GDPR” means: (a) the EU GDPR, where the EU GDPR applies; and (b) the UK GDPR, where the UK GDPR applies.

Personal Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data.

"Restricted Transfer" means: (a) where the EU GDPR applies, a transfer of personal data from the European Economic Area to a country outside of the European Economic Area which is not subject to an adequacy determination by the European Commission; (b) where the UK GDPR applies, a transfer of personal data from the United Kingdom to any other country which is not based on adequacy regulations pursuant to Section 17A of the United Kingdom Data Protection Act 2018; and (c) where the Swiss FDPA applies, a transfer of personal data from Switzerland to any other country that has not been determined to provide adequate data protection by the Federal Data Protection and Information Commissioner or other competent Swiss authority. For the avoidance of doubt, a transfer of personal data to the United States pursuant to the Data Privacy Framework shall not be a Restricted Transfer.

"Standard Contractual Clauses" means: (a) where the EU GDPR applies, the contractual clauses annexed to the European Commission's Implementing Decision 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council ("EU SCCs"); and (b) where the UK GDPR applies, the “International Data Transfer Addendum to the EU Commission Standard Contractual Clauses” issued by the Information Commissioner under s.119A(1) of the UK Data Protection Act 2018 (“UK Addendum”).

1.2. Legislative Definitions. In this DPA:

personal data” means the “personal data”, “personal information”, or analogous terms, as defined in Applicable Data Protection Laws, which is processed by Twingate on behalf of the Customer in connection with the Agreement.

The terms “data subject”, “process”, “processing”, “controller”, and “processor” as used in this DPA have the meanings given by Applicable Data Protection Laws or, absent any such meaning or law, by the EU GDPR.

The terms “data subject”, “controller” and “processor” include “consumer”, “business”, and “service provider”, respectively, as required by Applicable Data Protection Laws.

The terms “Business”, “Consumer”, “Sell”, “Service Provider”, “Share”, and “Targeted Advertising” have the meanings given to them in Applicable U.S. Privacy Laws.

1.3. Interpretation. Capitalized terms used but not otherwise defined in this DPA have the meanings given to them in the Agreement.

PART B: COMMON PROVISIONS

2. Roles of the Parties

2.1. Customer. The parties acknowledge that Customer is either: (a) a controller of personal data; or (b) acting as a processor on behalf of other controllers and, to the extent required under Applicable Data Protection Laws, has been instructed by and obtained the authorization of such controllers to agree to the processing of personal data by Twingate as Customer’s subprocessor as set forth in this DPA.

2.2. Twingate. Customer appoints Twingate as a processor to process personal data for the Purposes (as defined in Annex 1 of this DPA) in the context of the Services.

3. Obligations of Customer

3.1. General Compliance. Customer will:

(a) comply with Applicable Data Protection Laws when processing personal data and will only give lawful instructions to Twingate;

(b) implement appropriate technical and organizational measures to ensure, and to be able to demonstrate, that the processing of personal data is performed in accordance with Applicable Data Protection Laws; and

(c) cooperate with Twingate to fulfill their respective data protection compliance obligations in accordance with Applicable Data Protection Laws.

3.2. Controller Obligations. If Customer is a controller, Customer confirms and warrants that, in relation to the processing of personal data for the Purposes in the context of the Services:

(a) it has informed data subjects of the uses of personal data as required by Applicable Data Protection Laws;

(b) it relies on a valid legal basis for the processing of personal data under Applicable Data Protection Laws including, if required, obtaining consent from data subjects;

(c) it complies with data subject requests to exercise their rights of access, rectification, erasure, data portability, restriction of processing, and objection to the processing; and

(d) it complies with data accuracy, proportionality and data retention principles.

4. Obligations of Twingate

4.1. Processor Obligations. Twingate will comply with Applicable Data Protection Laws when processing personal data for the Purposes in connection with the Services. To the extent required by Applicable Data Protection Laws, Twingate will:

(a) only process personal data on behalf of Customer in accordance with Customer’s lawful written instructions and not for any other purposes than those specified in Annex 1 of this DPA or as otherwise agreed by both parties in writing;

(b) promptly inform Customer if, in its opinion, Customer’s instructions violate Applicable Data Protection Laws, or if Twingate is unable to comply with Customer’s instructions, in which case Twingate may, without breaching this DPA, suspend processing as necessary until the parties come to a resolution;

(c) notify Customer without undue delay after becoming aware of a Personal Data Breach. Twingate will take reasonable steps to mitigate the effects and to minimize any damage resulting from the Personal Data Breach;

(d) solely to the extent required by Applicable Data Protection Laws:

(i) assist Customer in complying with data protection impact assessments, and prior consultations with supervisory authorities’ requirements under Applicable Data Protection Laws, taking into account the nature of the processing and the information available to Twingate. To the extent authorized under applicable law, Customer shall be responsible for any costs arising from Twingate’s provision of such assistance that Twingate reasonably considers is unduly burdensome or onerous;
(ii) assist Customer in complying with data breach notifications under Applicable Data Protection Laws, taking into account the nature of the processing and the information available to Twingate; and
(iii) taking into account the nature of the processing, assist Customer, upon Customer’s written request, by appropriate technical and organizational measures, insofar as this is possible, to fulfill Customer’s obligation to respond to data subjects’ requests (or, if the Customer is a processor, to assist the applicable controller to respond to such requests) to exercise their rights as provided under Applicable Data Protection Laws and specified in this DPA;

(e) upon termination of the DPA or upon a request to delete or return personal data, delete (including by anonymization) or return all personal data, and delete (including by anonymization) existing copies unless applicable law prevents it from returning or destroying all or part of the personal data, or requires continued processing of the personal data (in which case the protective provisions of this DPA will continue to apply to such personal data).

5. Sub-processing

5.1. Authorization. Customer gives a general authorization to Twingate to engage other processors (“Subprocessors”) to process personal data in accordance with this DPA, including Twingate’s existing Subprocessors which are listed at https://www.twingate.com/privacy/subprocessors (“Subprocessor List”). Twingate will impose data protection obligations on Subprocessors to protect the personal data to the same standard as provided for by this DPA. Twingate will remain liable to Customer for each Subprocessor’s performance of such obligations. For the avoidance of doubt, if only some provisions of this DPA apply to a Subprocessor, Twingate is not obligated to impose inapplicable provisions on that Subprocessor - for example, if a Subprocessor only processes personal data regarding U.S. data subjects and thus does not process any personal data that Twingate has received via a Restricted Transfer, Twingate need not impose the Standard Contractual Clauses on such Subprocessor. Twingate will take steps to select and retain Subprocessors that are capable of maintaining appropriate privacy and security measures to protect personal data consistent with Applicable Data Protection Laws.

5.2 New Subprocessors.

(a) Twingate may subcontract the processing of any personal data to additional third party Subprocessors (each a “New Subprocessor”) by updating the Subprocessor List, provided that Twingate will update the Subprocessor List at least 10 days before authorizing any New Subprocessor to process personal data in connection with the provision of the applicable Services. Customer will be notified of updates to the Subprocessor List if Customer subscribes to update notifications by following the relevant instructions on the Subprocessor List webpage.

(b) Within 30 days of Twingate adding a New Subprocessor to the Subprocessor List, Customer may object in writing to Twingate’s appointment of that New Subprocessor on the basis that such addition would cause Customer to violate applicable legal requirements. Customer’s written objection will include Customer’s specific reasons for its objection and any options that may be available to mitigate. If Customer provides such a written objection to Twingate, the parties will cooperate to attempt to find a feasible solution. If a solution is not found and Customer does not withdraw its objection, Twingate will notify Customer in writing within 30 days that either: (i) Twingate will not use the New Subprocessor to process the personal data; or (ii) Twingate is unable or unwilling to refrain from using the New Subprocessor. If the notification in clause (ii) is given, Customer may, within 30 days of such notification, elect to terminate this DPA and the Agreement upon written notice to Twingate.

6. Security

6.1. Appropriate Security Measures. Twingate will implement appropriate technical and organizational measures to ensure a level of security with respect to the processing of personal data that is appropriate to the risk. In assessing the appropriate level of security, Twingate will take into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of data subjects and the risks that are presented by the processing, in particular from accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored or otherwise processed. Twingate will take steps to ensure that any person acting under its authority who has access to personal data is bound by enforceable contractual or statutory confidentiality obligations.

7. Data Protection Audit

7.1. Audit Right. Upon prior written request by Customer, Twingate agrees to cooperate and, within a reasonable timeframe, provide Customer with: (a) a summary of the audit reports, if any are available, demonstrating Twingate’s compliance with its obligations under this DPA, after redacting any confidential and commercially sensitive information; and (b) confirmation that the audit has not revealed any material vulnerability in Twingate’s systems, or to the extent that any such vulnerability was detected, that Twingate has remediated such vulnerability.

If the above measures are not sufficient to confirm compliance with Applicable Data Protection Laws or reveal some material issues, subject to confidentiality obligations, Twingate allows Customer to request an audit of Twingate’s data protection compliance program by Customer or by external independent auditors which are jointly selected by the parties. Any external independent auditor cannot be a competitor of Twingate, and the parties will agree upon the scope, timing, and duration of the audit (which must be conducted during Twingate’s regular business hours and with reasonable advance notice). Twingate will make available to Customer the result of the audit of its data protection compliance program. Customer will reimburse Twingate for all expenses and costs for such audit. The audit right hereunder may be exercised once in a calendar year during the term of this DPA and in addition where it is reasonably suspected that a Personal Data Breach has occurred.

PART C: SPECIFIC DATA PROTECTION LAWS

8. Personal Data Subject to the GDPR and Swiss FDPA

8.1. Data Transfers - Standard Contractual Clauses. To the extent that Customer undertakes a Restricted Transfer of personal data to Twingate, then:

(a) in relation to personal data that is protected by the EU GDPR, the EU SCCs will apply and are deemed completed as follows:

(i) Module Two will apply to the extent that Customer is a controller of the personal data, and Module Three will apply to the extent that Customer is a processor of the personal data on behalf of a third party controller;
(ii) in Clause 7, the optional docking clause will apply;
(iii) in Clause 9, Option 2 will apply, and the time period for prior notice of subprocessor changes shall be as set out in Section 5.2(a) of this DPA;
(iv) in Clause 11, the optional language will not apply;
(v) in Clause 17, Option 1 will apply, and the EU SCCs will be governed by the laws of Ireland;
(vi) in Clause 18(b), disputes shall be resolved before the courts of Ireland;
(vii) Annex I of the EU SCCs shall be deemed completed with the information set out in Annex 1 to this DPA; and
(viii) Annex II of the EU SCCs shall be deemed completed with the information set out in Annex 2 to this DPA;

(b) in relation to personal data that is protected by the UK GDPR, the UK Addendum will apply, and is deemed completed as follows:

(i) the EU SCCs, completed as set forth above in Section 8.1(a) of this DPA shall also apply to transfers of such personal data, subject to paragraph (ii) below; and
(ii) Tables 1 to 3 of the UK Addendum shall be deemed completed with relevant information from the EU SCCs, completed as set forth above, and the option “neither Party” shall be deemed to be selected in Table 4. The start date of the UK Addendum (as set forth in Table 1) shall be the date of this DPA; and

(c) in relation to personal data that is protected by the Swiss FDPA, the EU SCCs will apply in the form set out in Section 8.1(a) above with the following modifications:

(i) references to ‘Regulation (EU) 2016/679’ are interpreted as references to the Swiss FDPA;
(ii) references to specific articles of ‘Regulation (EU) 2016/679’ are replaced with the equivalent article or section of the Swiss FDPA;
(iii) references to ‘EU’, ‘Union’ and ‘Member State’ are replaced with ‘Switzerland’;
(iv) Clause 13(a) and Part C of Annex 2 are not used and the ‘competent supervisory authority’ is the Swiss Federal Data Protection and Information Commissioner;
(v) references to the ‘competent supervisory authority’ and ‘competent courts’ are replaced with the ‘Swiss Federal Data Protection and Information Commissioner’ and ‘applicable courts of Switzerland’;
(vi) in Clause 17, the EU SCCs are governed by the laws of Switzerland; and
(vii) in Clause 18(b), disputes will be resolved before the competent courts of Switzerland.

8.2. Application of SCCs. Where the Standard Contractual Clauses apply:

(a) As between the parties, any claims brought under the Standard Contractual Clauses shall be subject to the terms and conditions, including but not limited to, the exclusions and limitations set forth in the Agreement. In no event shall any party limit its liability towards any data subject or data protection authority under the Standard Contractual Clauses.

(b) Customer acknowledges that it shall exercise any right of audit it may have under the Standard Contractual Clauses by exercising its audit rights under Section 7 of this DPA (which shall be deemed to fulfil the Customer's audit rights under the Standard Contractual Clauses in full).

(c) In the event of any conflict between this DPA and the Standard Contractual Clauses, the Standard Contractual Clauses shall prevail.

9. Personal Data Subject to Applicable U.S. Privacy Laws

9.1. Application of U.S. Privacy Laws. This Section 9 applies solely to the extent that Applicable U.S. Privacy Laws apply to the processing of personal data and supplements Part B of the DPA. For clarity, Twingate shall process personal data solely for the Purposes and as described under the heading “Activities relevant to the data transferred under these clauses” in the data importer section of Annex 1. Twingate will process personal data: (a) to fulfill its obligations to Customer for performance of the Purposes, including this Section 9; (b) on Customer’s behalf; and (c) in compliance with Applicable U.S. Privacy Laws. Twingate certifies that it understands and will comply with the restrictions in this Section 9.

9.2. Restrictions. Twingate will:

(a) not retain, use, or disclose personal data outside of the direct business relationship between Customer and Twingate;

(b) not retain, use, or disclose personal data for any purpose, including any commercial purpose, other than the Purposes, unless expressly permitted by Applicable U.S. Privacy Laws;

(c) not Sell or Share any personal data (as such terms are defined in Applicable U.S. Privacy Laws) to any third party or process such personal data for Targeted Advertising purposes;

(d) comply with any applicable restrictions under the CCPA on combining personal data with personal data that Twingate receives from, or on behalf of, another source, or that Twingate collects from any interaction between it and any individual;

(e) provide the same level of protection for personal data subject to the CCPA as is required under the CCPA as applicable to Customer; and

(f) promptly notify Customer if Twingate determines that it can no longer meet its obligations under this Section 9 or Applicable U.S. Privacy Laws.

9.3. Customer Rights. To the extent that the CCPA applies, Customer retains the right to: (a) take reasonable steps to ensure that Twingate uses the personal data in a manner consistent with the CCPA; and (b) upon reasonable prior written notice, take reasonable and appropriate steps to stop and remediate unauthorized processing of personal data.

PART D: MISCELLANEOUS COMMON PROVISIONS

10. General Terms

10.1. Liability Toward Data Subjects. The parties’ liability will be governed by the liability provisions in the Agreement. However, each party agrees that it will be liable to data subjects for the entire damage resulting from a violation of European Data Protection Law. If one party paid full compensation for the damage suffered, it is entitled to claim back from the other party that part of the compensation corresponding to the other party’s part of responsibility for the damage. For that purpose, both parties agree that Customer will be liable to data subjects for the entire damage resulting from a violation of European Data Protection Law with regard to processing of personal data, and that Twingate will only be liable to data subjects for the entire damage resulting from a violation of the obligations of European Data Protection Law directed to Twingate or where it has acted outside of or contrary to Customer’s lawful instructions. Twingate will be exempt from liability if it proves that it is not in any way responsible for the event giving rise to the damage.

10.2. Applicable Law. This DPA and the processing of personal data under it are governed by the laws of the State of California, except where Applicable Data Protection Laws require this DPA to be governed by the laws of the jurisdiction in which Customer is established.

10.3. Modification. This DPA may only be modified by a written amendment signed by each of the parties.

10.4. Invalidity and Severability. If any provision of this DPA is found by any court or administrative body of competent jurisdiction to be invalid or unenforceable, the invalidity or unenforceability of such provision shall not affect any other provision of this DPA and all provisions not affected by such invalidity or unenforceability will remain in full force and effect.

10.5. Term. This DPA continues until the earlier of: (a) the expiry of Customer’s entitlement to use and receive the Services, as set forth in the Agreement, and (b) the termination of the Agreement.

10.6. Liability. In no event shall Twingate’s liability to Customer in connection with any issue arising out of, or in connection with, this DPA exceed Twingate’s limitations on liability set out in the Agreement. Twingate’s limitations on liability as set out in the Agreement shall apply in aggregate across both the Agreement and this DPA, such that a single limitation on liability regime shall apply across both the Agreement and this DPA.

* * *

Annex 1: Description of the processing

This Annex 1 describes the processing that Twingate will perform on behalf of Customer.

A. LIST OF PARTIES

Data exporter:

Name: Customer.

Contact details: The email address under which any of Customer’s Admin Accounts is registered.

Activities relevant to the data transferred under these clauses: The receipt of the Services provided by Twingate pursuant to the Agreement.

Signature and date: These Standard Contractual Clauses shall be deemed executed by Customer upon execution or acceptance of the Agreement.

Role (controller/processor): Controller or processor, depending on the circumstances (see Section 2 of this DPA).

Data importer:

Name: Twingate Inc.

Contact details: Twingate Privacy Team, privacy@twingate.com, 541 Jefferson Ave, Suite 100, Redwood City, CA 94063, USA.

Activities relevant to the data transferred under these clauses: The provision of the Services by Twingate pursuant to the Agreement. In general, Twingate provides services that are designed to enable Customer to manage, secure, and monitor access to systems, networks, devices, files, and other assets operated and made available by Customer.

Signature and date: These Standard Contractual Clauses shall be deemed executed by Twingate upon execution or acceptance of the Agreement.

Role (controller/processor): Processor.

B. DESCRIPTION OF TRANSFER

Categories of data subjects whose personal data is transferred: Customer may submit personal data to the Services, the extent of which is determined and controlled by Customer and may include, without limitation, personal data relating to the following categories of data subjects:

  • Employees, agents, advisors, contractors of Customer (and applicable Controllers, if Customer is a Processor) who are natural persons;

  • Employees or contact persons of Customer’s (and applicable Controllers’, if Customer is a Processor) business partners and vendors;

  • Customer’s end users who are authorized by Customer to use the Services.

Categories of personal data transferred: Customer may submit personal data to the Services, the extent of which is determined and controlled by the Customer and may include, without limitation, the following categories of personal data: name, email address, professional life data (e.g. job titles, department membership), device identifiers, network identifiers, network access activity, and localization data.

Sensitive data transferred (if applicable) and applied restrictions or safeguards that fully take into consideration the nature of the data and the risks involved, such as for instance strict purpose limitation, access restrictions (including access only for staff having followed specialised training), keeping a record of access to the data, restrictions for onward transfers or additional security measures: None.

The frequency of the transfer (e.g. whether the data is transferred on a one-off or continuous basis): Continuous throughout the duration of the Agreement.

Nature of the processing: The provision of the Services by Twingate to Customer pursuant to the Agreement.

Purpose(s) of the data transfer and further processing ("Purposes"): Customer will transfer personal data to Twingate for Twingate to provide the Services pursuant to the Agreement.

The period for which the personal data will be retained, or, if that is not possible, the criteria used to determine that period: Twingate will process personal data for the duration of the Agreement, unless otherwise agreed upon in writing.

For transfers to (sub-)processors, also specify subject matter, nature and duration of the processing: As described above and in the Agreement.

C. COMPETENT SUPERVISORY AUTHORITY

Identify the competent supervisory authority/ies (e.g. in accordance with Clause 13 of the Standard Contractual Clauses): The competent supervisory authority shall be determined in accordance with Clause 13 of the Standard Contractual Clauses, and to the extent legally permissible, shall be the Irish Data Protection Commission.

* * *

Annex 2: Technical and Organizational Measures

Description of the technical and organizational measures implemented by the processor(s)/data importer(s) (including any relevant certifications) to ensure an appropriate level of security, taking into account the nature, scope, context and purpose of the processing, and the risks for the rights and freedoms of natural persons.

Twingate’s technical and organizational security measures are described at https://www.twingate.com/docs/twingate-security/ and shall be deemed incorporated into these Standard Contractual Clauses. Twingate shall not modify these measures in a way that may adversely reduce the security of personal data it processes.

For transfers to Subprocessors, also describe the specific technical and organizational measures to be taken by the Subprocessor to be able to provide assistance to the controller (and, for transfers from a processor to a Subprocessor, to the data exporter).

When Twingate engages a subprocessor pursuant to this DPA, Twingate and the subprocessor enter into an agreement with applicable data protection obligations substantially similar to those contained in this DPA. Each subprocessor agreement must ensure that Twingate is able to meet its obligations to Customer. In addition to implementing technical and organizational measures to protect personal data, subprocessors must: (a) notify Twingate in the event of a Personal Data Breach so Twingate may notify Customer; (b) delete personal data when instructed by Twingate in accordance with Customer’s instructions to Twingate; (c) not engage additional subprocessors without Twingate’s authorization; and (d) not process personal data in a manner which conflicts with Customer’s instructions to Twingate.

* * *

Archived Versions

Data Processing Addendum

Last updated: September 1, 2026

This Data Processing Addendum (“DPA”) forms a part of the Customer Agreement or if you (“Customer”) have entered into a separate agreement with Twingate Inc. (“Twingate”), then it forms a part of such written agreement, if incorporated by reference in such agreement (in either case, the “Agreement”).

By executing an Agreement that explicitly states that this DPA is incorporated by reference, Customer enters into this DPA on behalf of itself and, to the extent required under Applicable Data Protection Laws, in the name and on behalf of any of its affiliates who are authorized to use the Services.

If you are entering into this DPA on behalf of a company or other legal entity, you represent and warrant that you have the authority to bind that legal entity to this DPA. In that case, “Customer” will refer to that company or other legal entity.


PART A: DEFINITIONS & INTERPRETATION

1. Definitions

1.1. Definitions. In this DPA:

Applicable Data Protection Laws” has the meaning given to that term in the Agreement.

Applicable U.S. Privacy Laws” means the CCPA, the Virginia Consumer Data Protection Act, the Colorado Privacy Act, the Utah Consumer Privacy Act, the Connecticut Data Privacy Act, and any other U.S. state or federal laws governing personal data contained in the Customer Data.

CCPA” means the California Consumer Privacy Act of 2018, as amended, or any successor legislation.

Data Privacy Framework” or “DPF” means the EU-U.S. Data Privacy Framework (“EU-US DPF”), the UK Extension to the EU-U.S. DPF (“UK-US Extension”), and the Swiss-U.S. Data Privacy Framework (“Swiss-US DPF”) as set forth by the U.S. Department of Commerce.

Europe” means the European Economic Area (“EEA”), Switzerland, and the United Kingdom.

European Data Protection Law” means: (a) Regulation 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the Processing of Personal Data and on the free movement of such data (General Data Protection Regulation) (the "EU GDPR"); (b) the EU e-Privacy Directive (Directive 2002/58/EC); (c) the EU GDPR as saved into United Kingdom law by virtue of section 3 of the United Kingdom's European Union (Withdrawal) Act 2018 (the "UK GDPR"); (d) the Swiss Federal Act on Data Protection of 25 September 2020 and its corresponding ordinances ("Swiss FDPA"); and (e) any and all applicable national data protection laws made under, pursuant to or that apply in conjunction with any of (a), (b) or (c); in each case as may be amended or superseded from time to time.

GDPR” means: (a) the EU GDPR, where the EU GDPR applies; and (b) the UK GDPR, where the UK GDPR applies.

Personal Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data.

"Restricted Transfer" means: (a) where the EU GDPR applies, a transfer of personal data from the European Economic Area to a country outside of the European Economic Area which is not subject to an adequacy determination by the European Commission; (b) where the UK GDPR applies, a transfer of personal data from the United Kingdom to any other country which is not based on adequacy regulations pursuant to Section 17A of the United Kingdom Data Protection Act 2018; and (c) where the Swiss FDPA applies, a transfer of personal data from Switzerland to any other country that has not been determined to provide adequate data protection by the Federal Data Protection and Information Commissioner or other competent Swiss authority. For the avoidance of doubt, a transfer of personal data to the United States pursuant to the Data Privacy Framework shall not be a Restricted Transfer.

"Standard Contractual Clauses" means: (a) where the EU GDPR applies, the contractual clauses annexed to the European Commission's Implementing Decision 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council ("EU SCCs"); and (b) where the UK GDPR applies, the “International Data Transfer Addendum to the EU Commission Standard Contractual Clauses” issued by the Information Commissioner under s.119A(1) of the UK Data Protection Act 2018 (“UK Addendum”).

1.2. Legislative Definitions. In this DPA:

personal data” means the “personal data”, “personal information”, or analogous terms, as defined in Applicable Data Protection Laws, which is processed by Twingate on behalf of the Customer in connection with the Agreement.

The terms “data subject”, “process”, “processing”, “controller”, and “processor” as used in this DPA have the meanings given by Applicable Data Protection Laws or, absent any such meaning or law, by the EU GDPR.

The terms “data subject”, “controller” and “processor” include “consumer”, “business”, and “service provider”, respectively, as required by Applicable Data Protection Laws.

The terms “Business”, “Consumer”, “Sell”, “Service Provider”, “Share”, and “Targeted Advertising” have the meanings given to them in Applicable U.S. Privacy Laws.

1.3. Interpretation. Capitalized terms used but not otherwise defined in this DPA have the meanings given to them in the Agreement.

PART B: COMMON PROVISIONS

2. Roles of the Parties

2.1. Customer. The parties acknowledge that Customer is either: (a) a controller of personal data; or (b) acting as a processor on behalf of other controllers and, to the extent required under Applicable Data Protection Laws, has been instructed by and obtained the authorization of such controllers to agree to the processing of personal data by Twingate as Customer’s subprocessor as set forth in this DPA.

2.2. Twingate. Customer appoints Twingate as a processor to process personal data for the Purposes (as defined in Annex 1 of this DPA) in the context of the Services.

3. Obligations of Customer

3.1. General Compliance. Customer will:

(a) comply with Applicable Data Protection Laws when processing personal data and will only give lawful instructions to Twingate;

(b) implement appropriate technical and organizational measures to ensure, and to be able to demonstrate, that the processing of personal data is performed in accordance with Applicable Data Protection Laws; and

(c) cooperate with Twingate to fulfill their respective data protection compliance obligations in accordance with Applicable Data Protection Laws.

3.2. Controller Obligations. If Customer is a controller, Customer confirms and warrants that, in relation to the processing of personal data for the Purposes in the context of the Services:

(a) it has informed data subjects of the uses of personal data as required by Applicable Data Protection Laws;

(b) it relies on a valid legal basis for the processing of personal data under Applicable Data Protection Laws including, if required, obtaining consent from data subjects;

(c) it complies with data subject requests to exercise their rights of access, rectification, erasure, data portability, restriction of processing, and objection to the processing; and

(d) it complies with data accuracy, proportionality and data retention principles.

4. Obligations of Twingate

4.1. Processor Obligations. Twingate will comply with Applicable Data Protection Laws when processing personal data for the Purposes in connection with the Services. To the extent required by Applicable Data Protection Laws, Twingate will:

(a) only process personal data on behalf of Customer in accordance with Customer’s lawful written instructions and not for any other purposes than those specified in Annex 1 of this DPA or as otherwise agreed by both parties in writing;

(b) promptly inform Customer if, in its opinion, Customer’s instructions violate Applicable Data Protection Laws, or if Twingate is unable to comply with Customer’s instructions, in which case Twingate may, without breaching this DPA, suspend processing as necessary until the parties come to a resolution;

(c) notify Customer without undue delay after becoming aware of a Personal Data Breach. Twingate will take reasonable steps to mitigate the effects and to minimize any damage resulting from the Personal Data Breach;

(d) solely to the extent required by Applicable Data Protection Laws:

(i) assist Customer in complying with data protection impact assessments, and prior consultations with supervisory authorities’ requirements under Applicable Data Protection Laws, taking into account the nature of the processing and the information available to Twingate. To the extent authorized under applicable law, Customer shall be responsible for any costs arising from Twingate’s provision of such assistance that Twingate reasonably considers is unduly burdensome or onerous;
(ii) assist Customer in complying with data breach notifications under Applicable Data Protection Laws, taking into account the nature of the processing and the information available to Twingate; and
(iii) taking into account the nature of the processing, assist Customer, upon Customer’s written request, by appropriate technical and organizational measures, insofar as this is possible, to fulfill Customer’s obligation to respond to data subjects’ requests (or, if the Customer is a processor, to assist the applicable controller to respond to such requests) to exercise their rights as provided under Applicable Data Protection Laws and specified in this DPA;

(e) upon termination of the DPA or upon a request to delete or return personal data, delete (including by anonymization) or return all personal data, and delete (including by anonymization) existing copies unless applicable law prevents it from returning or destroying all or part of the personal data, or requires continued processing of the personal data (in which case the protective provisions of this DPA will continue to apply to such personal data).

5. Sub-processing

5.1. Authorization. Customer gives a general authorization to Twingate to engage other processors (“Subprocessors”) to process personal data in accordance with this DPA, including Twingate’s existing Subprocessors which are listed at https://www.twingate.com/privacy/subprocessors (“Subprocessor List”). Twingate will impose data protection obligations on Subprocessors to protect the personal data to the same standard as provided for by this DPA. Twingate will remain liable to Customer for each Subprocessor’s performance of such obligations. For the avoidance of doubt, if only some provisions of this DPA apply to a Subprocessor, Twingate is not obligated to impose inapplicable provisions on that Subprocessor - for example, if a Subprocessor only processes personal data regarding U.S. data subjects and thus does not process any personal data that Twingate has received via a Restricted Transfer, Twingate need not impose the Standard Contractual Clauses on such Subprocessor. Twingate will take steps to select and retain Subprocessors that are capable of maintaining appropriate privacy and security measures to protect personal data consistent with Applicable Data Protection Laws.

5.2 New Subprocessors.

(a) Twingate may subcontract the processing of any personal data to additional third party Subprocessors (each a “New Subprocessor”) by updating the Subprocessor List, provided that Twingate will update the Subprocessor List at least 10 days before authorizing any New Subprocessor to process personal data in connection with the provision of the applicable Services. Customer will be notified of updates to the Subprocessor List if Customer subscribes to update notifications by following the relevant instructions on the Subprocessor List webpage.

(b) Within 30 days of Twingate adding a New Subprocessor to the Subprocessor List, Customer may object in writing to Twingate’s appointment of that New Subprocessor on the basis that such addition would cause Customer to violate applicable legal requirements. Customer’s written objection will include Customer’s specific reasons for its objection and any options that may be available to mitigate. If Customer provides such a written objection to Twingate, the parties will cooperate to attempt to find a feasible solution. If a solution is not found and Customer does not withdraw its objection, Twingate will notify Customer in writing within 30 days that either: (i) Twingate will not use the New Subprocessor to process the personal data; or (ii) Twingate is unable or unwilling to refrain from using the New Subprocessor. If the notification in clause (ii) is given, Customer may, within 30 days of such notification, elect to terminate this DPA and the Agreement upon written notice to Twingate.

6. Security

6.1. Appropriate Security Measures. Twingate will implement appropriate technical and organizational measures to ensure a level of security with respect to the processing of personal data that is appropriate to the risk. In assessing the appropriate level of security, Twingate will take into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of data subjects and the risks that are presented by the processing, in particular from accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored or otherwise processed. Twingate will take steps to ensure that any person acting under its authority who has access to personal data is bound by enforceable contractual or statutory confidentiality obligations.

7. Data Protection Audit

7.1. Audit Right. Upon prior written request by Customer, Twingate agrees to cooperate and, within a reasonable timeframe, provide Customer with: (a) a summary of the audit reports, if any are available, demonstrating Twingate’s compliance with its obligations under this DPA, after redacting any confidential and commercially sensitive information; and (b) confirmation that the audit has not revealed any material vulnerability in Twingate’s systems, or to the extent that any such vulnerability was detected, that Twingate has remediated such vulnerability.

If the above measures are not sufficient to confirm compliance with Applicable Data Protection Laws or reveal some material issues, subject to confidentiality obligations, Twingate allows Customer to request an audit of Twingate’s data protection compliance program by Customer or by external independent auditors which are jointly selected by the parties. Any external independent auditor cannot be a competitor of Twingate, and the parties will agree upon the scope, timing, and duration of the audit (which must be conducted during Twingate’s regular business hours and with reasonable advance notice). Twingate will make available to Customer the result of the audit of its data protection compliance program. Customer will reimburse Twingate for all expenses and costs for such audit. The audit right hereunder may be exercised once in a calendar year during the term of this DPA and in addition where it is reasonably suspected that a Personal Data Breach has occurred.

PART C: SPECIFIC DATA PROTECTION LAWS

8. Personal Data Subject to the GDPR and Swiss FDPA

8.1. Data Transfers - Standard Contractual Clauses. To the extent that Customer undertakes a Restricted Transfer of personal data to Twingate, then:

(a) in relation to personal data that is protected by the EU GDPR, the EU SCCs will apply and are deemed completed as follows:

(i) Module Two will apply to the extent that Customer is a controller of the personal data, and Module Three will apply to the extent that Customer is a processor of the personal data on behalf of a third party controller;
(ii) in Clause 7, the optional docking clause will apply;
(iii) in Clause 9, Option 2 will apply, and the time period for prior notice of subprocessor changes shall be as set out in Section 5.2(a) of this DPA;
(iv) in Clause 11, the optional language will not apply;
(v) in Clause 17, Option 1 will apply, and the EU SCCs will be governed by the laws of Ireland;
(vi) in Clause 18(b), disputes shall be resolved before the courts of Ireland;
(vii) Annex I of the EU SCCs shall be deemed completed with the information set out in Annex 1 to this DPA; and
(viii) Annex II of the EU SCCs shall be deemed completed with the information set out in Annex 2 to this DPA;

(b) in relation to personal data that is protected by the UK GDPR, the UK Addendum will apply, and is deemed completed as follows:

(i) the EU SCCs, completed as set forth above in Section 8.1(a) of this DPA shall also apply to transfers of such personal data, subject to paragraph (ii) below; and
(ii) Tables 1 to 3 of the UK Addendum shall be deemed completed with relevant information from the EU SCCs, completed as set forth above, and the option “neither Party” shall be deemed to be selected in Table 4. The start date of the UK Addendum (as set forth in Table 1) shall be the date of this DPA; and

(c) in relation to personal data that is protected by the Swiss FDPA, the EU SCCs will apply in the form set out in Section 8.1(a) above with the following modifications:

(i) references to ‘Regulation (EU) 2016/679’ are interpreted as references to the Swiss FDPA;
(ii) references to specific articles of ‘Regulation (EU) 2016/679’ are replaced with the equivalent article or section of the Swiss FDPA;
(iii) references to ‘EU’, ‘Union’ and ‘Member State’ are replaced with ‘Switzerland’;
(iv) Clause 13(a) and Part C of Annex 2 are not used and the ‘competent supervisory authority’ is the Swiss Federal Data Protection and Information Commissioner;
(v) references to the ‘competent supervisory authority’ and ‘competent courts’ are replaced with the ‘Swiss Federal Data Protection and Information Commissioner’ and ‘applicable courts of Switzerland’;
(vi) in Clause 17, the EU SCCs are governed by the laws of Switzerland; and
(vii) in Clause 18(b), disputes will be resolved before the competent courts of Switzerland.

8.2. Application of SCCs. Where the Standard Contractual Clauses apply:

(a) As between the parties, any claims brought under the Standard Contractual Clauses shall be subject to the terms and conditions, including but not limited to, the exclusions and limitations set forth in the Agreement. In no event shall any party limit its liability towards any data subject or data protection authority under the Standard Contractual Clauses.

(b) Customer acknowledges that it shall exercise any right of audit it may have under the Standard Contractual Clauses by exercising its audit rights under Section 7 of this DPA (which shall be deemed to fulfil the Customer's audit rights under the Standard Contractual Clauses in full).

(c) In the event of any conflict between this DPA and the Standard Contractual Clauses, the Standard Contractual Clauses shall prevail.

9. Personal Data Subject to Applicable U.S. Privacy Laws

9.1. Application of U.S. Privacy Laws. This Section 9 applies solely to the extent that Applicable U.S. Privacy Laws apply to the processing of personal data and supplements Part B of the DPA. For clarity, Twingate shall process personal data solely for the Purposes and as described under the heading “Activities relevant to the data transferred under these clauses” in the data importer section of Annex 1. Twingate will process personal data: (a) to fulfill its obligations to Customer for performance of the Purposes, including this Section 9; (b) on Customer’s behalf; and (c) in compliance with Applicable U.S. Privacy Laws. Twingate certifies that it understands and will comply with the restrictions in this Section 9.

9.2. Restrictions. Twingate will:

(a) not retain, use, or disclose personal data outside of the direct business relationship between Customer and Twingate;

(b) not retain, use, or disclose personal data for any purpose, including any commercial purpose, other than the Purposes, unless expressly permitted by Applicable U.S. Privacy Laws;

(c) not Sell or Share any personal data (as such terms are defined in Applicable U.S. Privacy Laws) to any third party or process such personal data for Targeted Advertising purposes;

(d) comply with any applicable restrictions under the CCPA on combining personal data with personal data that Twingate receives from, or on behalf of, another source, or that Twingate collects from any interaction between it and any individual;

(e) provide the same level of protection for personal data subject to the CCPA as is required under the CCPA as applicable to Customer; and

(f) promptly notify Customer if Twingate determines that it can no longer meet its obligations under this Section 9 or Applicable U.S. Privacy Laws.

9.3. Customer Rights. To the extent that the CCPA applies, Customer retains the right to: (a) take reasonable steps to ensure that Twingate uses the personal data in a manner consistent with the CCPA; and (b) upon reasonable prior written notice, take reasonable and appropriate steps to stop and remediate unauthorized processing of personal data.

PART D: MISCELLANEOUS COMMON PROVISIONS

10. General Terms

10.1. Liability Toward Data Subjects. The parties’ liability will be governed by the liability provisions in the Agreement. However, each party agrees that it will be liable to data subjects for the entire damage resulting from a violation of European Data Protection Law. If one party paid full compensation for the damage suffered, it is entitled to claim back from the other party that part of the compensation corresponding to the other party’s part of responsibility for the damage. For that purpose, both parties agree that Customer will be liable to data subjects for the entire damage resulting from a violation of European Data Protection Law with regard to processing of personal data, and that Twingate will only be liable to data subjects for the entire damage resulting from a violation of the obligations of European Data Protection Law directed to Twingate or where it has acted outside of or contrary to Customer’s lawful instructions. Twingate will be exempt from liability if it proves that it is not in any way responsible for the event giving rise to the damage.

10.2. Applicable Law. This DPA and the processing of personal data under it are governed by the laws of the State of California, except where Applicable Data Protection Laws require this DPA to be governed by the laws of the jurisdiction in which Customer is established.

10.3. Modification. This DPA may only be modified by a written amendment signed by each of the parties.

10.4. Invalidity and Severability. If any provision of this DPA is found by any court or administrative body of competent jurisdiction to be invalid or unenforceable, the invalidity or unenforceability of such provision shall not affect any other provision of this DPA and all provisions not affected by such invalidity or unenforceability will remain in full force and effect.

10.5. Term. This DPA continues until the earlier of: (a) the expiry of Customer’s entitlement to use and receive the Services, as set forth in the Agreement, and (b) the termination of the Agreement.

10.6. Liability. In no event shall Twingate’s liability to Customer in connection with any issue arising out of, or in connection with, this DPA exceed Twingate’s limitations on liability set out in the Agreement. Twingate’s limitations on liability as set out in the Agreement shall apply in aggregate across both the Agreement and this DPA, such that a single limitation on liability regime shall apply across both the Agreement and this DPA.

* * *

Annex 1: Description of the processing

This Annex 1 describes the processing that Twingate will perform on behalf of Customer.

A. LIST OF PARTIES

Data exporter:

Name: Customer.

Contact details: The email address under which any of Customer’s Admin Accounts is registered.

Activities relevant to the data transferred under these clauses: The receipt of the Services provided by Twingate pursuant to the Agreement.

Signature and date: These Standard Contractual Clauses shall be deemed executed by Customer upon execution or acceptance of the Agreement.

Role (controller/processor): Controller or processor, depending on the circumstances (see Section 2 of this DPA).

Data importer:

Name: Twingate Inc.

Contact details: Twingate Privacy Team, privacy@twingate.com, 541 Jefferson Ave, Suite 100, Redwood City, CA 94063, USA.

Activities relevant to the data transferred under these clauses: The provision of the Services by Twingate pursuant to the Agreement. In general, Twingate provides services that are designed to enable Customer to manage, secure, and monitor access to systems, networks, devices, files, and other assets operated and made available by Customer.

Signature and date: These Standard Contractual Clauses shall be deemed executed by Twingate upon execution or acceptance of the Agreement.

Role (controller/processor): Processor.

B. DESCRIPTION OF TRANSFER

Categories of data subjects whose personal data is transferred: Customer may submit personal data to the Services, the extent of which is determined and controlled by Customer and may include, without limitation, personal data relating to the following categories of data subjects:

  • Employees, agents, advisors, contractors of Customer (and applicable Controllers, if Customer is a Processor) who are natural persons;

  • Employees or contact persons of Customer’s (and applicable Controllers’, if Customer is a Processor) business partners and vendors;

  • Customer’s end users who are authorized by Customer to use the Services.

Categories of personal data transferred: Customer may submit personal data to the Services, the extent of which is determined and controlled by the Customer and may include, without limitation, the following categories of personal data: name, email address, professional life data (e.g. job titles, department membership), device identifiers, network identifiers, network access activity, and localization data.

Sensitive data transferred (if applicable) and applied restrictions or safeguards that fully take into consideration the nature of the data and the risks involved, such as for instance strict purpose limitation, access restrictions (including access only for staff having followed specialised training), keeping a record of access to the data, restrictions for onward transfers or additional security measures: None.

The frequency of the transfer (e.g. whether the data is transferred on a one-off or continuous basis): Continuous throughout the duration of the Agreement.

Nature of the processing: The provision of the Services by Twingate to Customer pursuant to the Agreement.

Purpose(s) of the data transfer and further processing ("Purposes"): Customer will transfer personal data to Twingate for Twingate to provide the Services pursuant to the Agreement.

The period for which the personal data will be retained, or, if that is not possible, the criteria used to determine that period: Twingate will process personal data for the duration of the Agreement, unless otherwise agreed upon in writing.

For transfers to (sub-)processors, also specify subject matter, nature and duration of the processing: As described above and in the Agreement.

C. COMPETENT SUPERVISORY AUTHORITY

Identify the competent supervisory authority/ies (e.g. in accordance with Clause 13 of the Standard Contractual Clauses): The competent supervisory authority shall be determined in accordance with Clause 13 of the Standard Contractual Clauses, and to the extent legally permissible, shall be the Irish Data Protection Commission.

* * *

Annex 2: Technical and Organizational Measures

Description of the technical and organizational measures implemented by the processor(s)/data importer(s) (including any relevant certifications) to ensure an appropriate level of security, taking into account the nature, scope, context and purpose of the processing, and the risks for the rights and freedoms of natural persons.

Twingate’s technical and organizational security measures are described at https://www.twingate.com/docs/twingate-security/ and shall be deemed incorporated into these Standard Contractual Clauses. Twingate shall not modify these measures in a way that may adversely reduce the security of personal data it processes.

For transfers to Subprocessors, also describe the specific technical and organizational measures to be taken by the Subprocessor to be able to provide assistance to the controller (and, for transfers from a processor to a Subprocessor, to the data exporter).

When Twingate engages a subprocessor pursuant to this DPA, Twingate and the subprocessor enter into an agreement with applicable data protection obligations substantially similar to those contained in this DPA. Each subprocessor agreement must ensure that Twingate is able to meet its obligations to Customer. In addition to implementing technical and organizational measures to protect personal data, subprocessors must: (a) notify Twingate in the event of a Personal Data Breach so Twingate may notify Customer; (b) delete personal data when instructed by Twingate in accordance with Customer’s instructions to Twingate; (c) not engage additional subprocessors without Twingate’s authorization; and (d) not process personal data in a manner which conflicts with Customer’s instructions to Twingate.

* * *

Archived Versions

Data Processing Addendum

Last updated: September 1, 2026

This Data Processing Addendum (“DPA”) forms a part of the Customer Agreement or if you (“Customer”) have entered into a separate agreement with Twingate Inc. (“Twingate”), then it forms a part of such written agreement, if incorporated by reference in such agreement (in either case, the “Agreement”).

By executing an Agreement that explicitly states that this DPA is incorporated by reference, Customer enters into this DPA on behalf of itself and, to the extent required under Applicable Data Protection Laws, in the name and on behalf of any of its affiliates who are authorized to use the Services.

If you are entering into this DPA on behalf of a company or other legal entity, you represent and warrant that you have the authority to bind that legal entity to this DPA. In that case, “Customer” will refer to that company or other legal entity.


PART A: DEFINITIONS & INTERPRETATION

1. Definitions

1.1. Definitions. In this DPA:

Applicable Data Protection Laws” has the meaning given to that term in the Agreement.

Applicable U.S. Privacy Laws” means the CCPA, the Virginia Consumer Data Protection Act, the Colorado Privacy Act, the Utah Consumer Privacy Act, the Connecticut Data Privacy Act, and any other U.S. state or federal laws governing personal data contained in the Customer Data.

CCPA” means the California Consumer Privacy Act of 2018, as amended, or any successor legislation.

Data Privacy Framework” or “DPF” means the EU-U.S. Data Privacy Framework (“EU-US DPF”), the UK Extension to the EU-U.S. DPF (“UK-US Extension”), and the Swiss-U.S. Data Privacy Framework (“Swiss-US DPF”) as set forth by the U.S. Department of Commerce.

Europe” means the European Economic Area (“EEA”), Switzerland, and the United Kingdom.

European Data Protection Law” means: (a) Regulation 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the Processing of Personal Data and on the free movement of such data (General Data Protection Regulation) (the "EU GDPR"); (b) the EU e-Privacy Directive (Directive 2002/58/EC); (c) the EU GDPR as saved into United Kingdom law by virtue of section 3 of the United Kingdom's European Union (Withdrawal) Act 2018 (the "UK GDPR"); (d) the Swiss Federal Act on Data Protection of 25 September 2020 and its corresponding ordinances ("Swiss FDPA"); and (e) any and all applicable national data protection laws made under, pursuant to or that apply in conjunction with any of (a), (b) or (c); in each case as may be amended or superseded from time to time.

GDPR” means: (a) the EU GDPR, where the EU GDPR applies; and (b) the UK GDPR, where the UK GDPR applies.

Personal Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data.

"Restricted Transfer" means: (a) where the EU GDPR applies, a transfer of personal data from the European Economic Area to a country outside of the European Economic Area which is not subject to an adequacy determination by the European Commission; (b) where the UK GDPR applies, a transfer of personal data from the United Kingdom to any other country which is not based on adequacy regulations pursuant to Section 17A of the United Kingdom Data Protection Act 2018; and (c) where the Swiss FDPA applies, a transfer of personal data from Switzerland to any other country that has not been determined to provide adequate data protection by the Federal Data Protection and Information Commissioner or other competent Swiss authority. For the avoidance of doubt, a transfer of personal data to the United States pursuant to the Data Privacy Framework shall not be a Restricted Transfer.

"Standard Contractual Clauses" means: (a) where the EU GDPR applies, the contractual clauses annexed to the European Commission's Implementing Decision 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council ("EU SCCs"); and (b) where the UK GDPR applies, the “International Data Transfer Addendum to the EU Commission Standard Contractual Clauses” issued by the Information Commissioner under s.119A(1) of the UK Data Protection Act 2018 (“UK Addendum”).

1.2. Legislative Definitions. In this DPA:

personal data” means the “personal data”, “personal information”, or analogous terms, as defined in Applicable Data Protection Laws, which is processed by Twingate on behalf of the Customer in connection with the Agreement.

The terms “data subject”, “process”, “processing”, “controller”, and “processor” as used in this DPA have the meanings given by Applicable Data Protection Laws or, absent any such meaning or law, by the EU GDPR.

The terms “data subject”, “controller” and “processor” include “consumer”, “business”, and “service provider”, respectively, as required by Applicable Data Protection Laws.

The terms “Business”, “Consumer”, “Sell”, “Service Provider”, “Share”, and “Targeted Advertising” have the meanings given to them in Applicable U.S. Privacy Laws.

1.3. Interpretation. Capitalized terms used but not otherwise defined in this DPA have the meanings given to them in the Agreement.

PART B: COMMON PROVISIONS

2. Roles of the Parties

2.1. Customer. The parties acknowledge that Customer is either: (a) a controller of personal data; or (b) acting as a processor on behalf of other controllers and, to the extent required under Applicable Data Protection Laws, has been instructed by and obtained the authorization of such controllers to agree to the processing of personal data by Twingate as Customer’s subprocessor as set forth in this DPA.

2.2. Twingate. Customer appoints Twingate as a processor to process personal data for the Purposes (as defined in Annex 1 of this DPA) in the context of the Services.

3. Obligations of Customer

3.1. General Compliance. Customer will:

(a) comply with Applicable Data Protection Laws when processing personal data and will only give lawful instructions to Twingate;

(b) implement appropriate technical and organizational measures to ensure, and to be able to demonstrate, that the processing of personal data is performed in accordance with Applicable Data Protection Laws; and

(c) cooperate with Twingate to fulfill their respective data protection compliance obligations in accordance with Applicable Data Protection Laws.

3.2. Controller Obligations. If Customer is a controller, Customer confirms and warrants that, in relation to the processing of personal data for the Purposes in the context of the Services:

(a) it has informed data subjects of the uses of personal data as required by Applicable Data Protection Laws;

(b) it relies on a valid legal basis for the processing of personal data under Applicable Data Protection Laws including, if required, obtaining consent from data subjects;

(c) it complies with data subject requests to exercise their rights of access, rectification, erasure, data portability, restriction of processing, and objection to the processing; and

(d) it complies with data accuracy, proportionality and data retention principles.

4. Obligations of Twingate

4.1. Processor Obligations. Twingate will comply with Applicable Data Protection Laws when processing personal data for the Purposes in connection with the Services. To the extent required by Applicable Data Protection Laws, Twingate will:

(a) only process personal data on behalf of Customer in accordance with Customer’s lawful written instructions and not for any other purposes than those specified in Annex 1 of this DPA or as otherwise agreed by both parties in writing;

(b) promptly inform Customer if, in its opinion, Customer’s instructions violate Applicable Data Protection Laws, or if Twingate is unable to comply with Customer’s instructions, in which case Twingate may, without breaching this DPA, suspend processing as necessary until the parties come to a resolution;

(c) notify Customer without undue delay after becoming aware of a Personal Data Breach. Twingate will take reasonable steps to mitigate the effects and to minimize any damage resulting from the Personal Data Breach;

(d) solely to the extent required by Applicable Data Protection Laws:

(i) assist Customer in complying with data protection impact assessments, and prior consultations with supervisory authorities’ requirements under Applicable Data Protection Laws, taking into account the nature of the processing and the information available to Twingate. To the extent authorized under applicable law, Customer shall be responsible for any costs arising from Twingate’s provision of such assistance that Twingate reasonably considers is unduly burdensome or onerous;
(ii) assist Customer in complying with data breach notifications under Applicable Data Protection Laws, taking into account the nature of the processing and the information available to Twingate; and
(iii) taking into account the nature of the processing, assist Customer, upon Customer’s written request, by appropriate technical and organizational measures, insofar as this is possible, to fulfill Customer’s obligation to respond to data subjects’ requests (or, if the Customer is a processor, to assist the applicable controller to respond to such requests) to exercise their rights as provided under Applicable Data Protection Laws and specified in this DPA;

(e) upon termination of the DPA or upon a request to delete or return personal data, delete (including by anonymization) or return all personal data, and delete (including by anonymization) existing copies unless applicable law prevents it from returning or destroying all or part of the personal data, or requires continued processing of the personal data (in which case the protective provisions of this DPA will continue to apply to such personal data).

5. Sub-processing

5.1. Authorization. Customer gives a general authorization to Twingate to engage other processors (“Subprocessors”) to process personal data in accordance with this DPA, including Twingate’s existing Subprocessors which are listed at https://www.twingate.com/privacy/subprocessors (“Subprocessor List”). Twingate will impose data protection obligations on Subprocessors to protect the personal data to the same standard as provided for by this DPA. Twingate will remain liable to Customer for each Subprocessor’s performance of such obligations. For the avoidance of doubt, if only some provisions of this DPA apply to a Subprocessor, Twingate is not obligated to impose inapplicable provisions on that Subprocessor - for example, if a Subprocessor only processes personal data regarding U.S. data subjects and thus does not process any personal data that Twingate has received via a Restricted Transfer, Twingate need not impose the Standard Contractual Clauses on such Subprocessor. Twingate will take steps to select and retain Subprocessors that are capable of maintaining appropriate privacy and security measures to protect personal data consistent with Applicable Data Protection Laws.

5.2 New Subprocessors.

(a) Twingate may subcontract the processing of any personal data to additional third party Subprocessors (each a “New Subprocessor”) by updating the Subprocessor List, provided that Twingate will update the Subprocessor List at least 10 days before authorizing any New Subprocessor to process personal data in connection with the provision of the applicable Services. Customer will be notified of updates to the Subprocessor List if Customer subscribes to update notifications by following the relevant instructions on the Subprocessor List webpage.

(b) Within 30 days of Twingate adding a New Subprocessor to the Subprocessor List, Customer may object in writing to Twingate’s appointment of that New Subprocessor on the basis that such addition would cause Customer to violate applicable legal requirements. Customer’s written objection will include Customer’s specific reasons for its objection and any options that may be available to mitigate. If Customer provides such a written objection to Twingate, the parties will cooperate to attempt to find a feasible solution. If a solution is not found and Customer does not withdraw its objection, Twingate will notify Customer in writing within 30 days that either: (i) Twingate will not use the New Subprocessor to process the personal data; or (ii) Twingate is unable or unwilling to refrain from using the New Subprocessor. If the notification in clause (ii) is given, Customer may, within 30 days of such notification, elect to terminate this DPA and the Agreement upon written notice to Twingate.

6. Security

6.1. Appropriate Security Measures. Twingate will implement appropriate technical and organizational measures to ensure a level of security with respect to the processing of personal data that is appropriate to the risk. In assessing the appropriate level of security, Twingate will take into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of data subjects and the risks that are presented by the processing, in particular from accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored or otherwise processed. Twingate will take steps to ensure that any person acting under its authority who has access to personal data is bound by enforceable contractual or statutory confidentiality obligations.

7. Data Protection Audit

7.1. Audit Right. Upon prior written request by Customer, Twingate agrees to cooperate and, within a reasonable timeframe, provide Customer with: (a) a summary of the audit reports, if any are available, demonstrating Twingate’s compliance with its obligations under this DPA, after redacting any confidential and commercially sensitive information; and (b) confirmation that the audit has not revealed any material vulnerability in Twingate’s systems, or to the extent that any such vulnerability was detected, that Twingate has remediated such vulnerability.

If the above measures are not sufficient to confirm compliance with Applicable Data Protection Laws or reveal some material issues, subject to confidentiality obligations, Twingate allows Customer to request an audit of Twingate’s data protection compliance program by Customer or by external independent auditors which are jointly selected by the parties. Any external independent auditor cannot be a competitor of Twingate, and the parties will agree upon the scope, timing, and duration of the audit (which must be conducted during Twingate’s regular business hours and with reasonable advance notice). Twingate will make available to Customer the result of the audit of its data protection compliance program. Customer will reimburse Twingate for all expenses and costs for such audit. The audit right hereunder may be exercised once in a calendar year during the term of this DPA and in addition where it is reasonably suspected that a Personal Data Breach has occurred.

PART C: SPECIFIC DATA PROTECTION LAWS

8. Personal Data Subject to the GDPR and Swiss FDPA

8.1. Data Transfers - Standard Contractual Clauses. To the extent that Customer undertakes a Restricted Transfer of personal data to Twingate, then:

(a) in relation to personal data that is protected by the EU GDPR, the EU SCCs will apply and are deemed completed as follows:

(i) Module Two will apply to the extent that Customer is a controller of the personal data, and Module Three will apply to the extent that Customer is a processor of the personal data on behalf of a third party controller;
(ii) in Clause 7, the optional docking clause will apply;
(iii) in Clause 9, Option 2 will apply, and the time period for prior notice of subprocessor changes shall be as set out in Section 5.2(a) of this DPA;
(iv) in Clause 11, the optional language will not apply;
(v) in Clause 17, Option 1 will apply, and the EU SCCs will be governed by the laws of Ireland;
(vi) in Clause 18(b), disputes shall be resolved before the courts of Ireland;
(vii) Annex I of the EU SCCs shall be deemed completed with the information set out in Annex 1 to this DPA; and
(viii) Annex II of the EU SCCs shall be deemed completed with the information set out in Annex 2 to this DPA;

(b) in relation to personal data that is protected by the UK GDPR, the UK Addendum will apply, and is deemed completed as follows:

(i) the EU SCCs, completed as set forth above in Section 8.1(a) of this DPA shall also apply to transfers of such personal data, subject to paragraph (ii) below; and
(ii) Tables 1 to 3 of the UK Addendum shall be deemed completed with relevant information from the EU SCCs, completed as set forth above, and the option “neither Party” shall be deemed to be selected in Table 4. The start date of the UK Addendum (as set forth in Table 1) shall be the date of this DPA; and

(c) in relation to personal data that is protected by the Swiss FDPA, the EU SCCs will apply in the form set out in Section 8.1(a) above with the following modifications:

(i) references to ‘Regulation (EU) 2016/679’ are interpreted as references to the Swiss FDPA;
(ii) references to specific articles of ‘Regulation (EU) 2016/679’ are replaced with the equivalent article or section of the Swiss FDPA;
(iii) references to ‘EU’, ‘Union’ and ‘Member State’ are replaced with ‘Switzerland’;
(iv) Clause 13(a) and Part C of Annex 2 are not used and the ‘competent supervisory authority’ is the Swiss Federal Data Protection and Information Commissioner;
(v) references to the ‘competent supervisory authority’ and ‘competent courts’ are replaced with the ‘Swiss Federal Data Protection and Information Commissioner’ and ‘applicable courts of Switzerland’;
(vi) in Clause 17, the EU SCCs are governed by the laws of Switzerland; and
(vii) in Clause 18(b), disputes will be resolved before the competent courts of Switzerland.

8.2. Application of SCCs. Where the Standard Contractual Clauses apply:

(a) As between the parties, any claims brought under the Standard Contractual Clauses shall be subject to the terms and conditions, including but not limited to, the exclusions and limitations set forth in the Agreement. In no event shall any party limit its liability towards any data subject or data protection authority under the Standard Contractual Clauses.

(b) Customer acknowledges that it shall exercise any right of audit it may have under the Standard Contractual Clauses by exercising its audit rights under Section 7 of this DPA (which shall be deemed to fulfil the Customer's audit rights under the Standard Contractual Clauses in full).

(c) In the event of any conflict between this DPA and the Standard Contractual Clauses, the Standard Contractual Clauses shall prevail.

9. Personal Data Subject to Applicable U.S. Privacy Laws

9.1. Application of U.S. Privacy Laws. This Section 9 applies solely to the extent that Applicable U.S. Privacy Laws apply to the processing of personal data and supplements Part B of the DPA. For clarity, Twingate shall process personal data solely for the Purposes and as described under the heading “Activities relevant to the data transferred under these clauses” in the data importer section of Annex 1. Twingate will process personal data: (a) to fulfill its obligations to Customer for performance of the Purposes, including this Section 9; (b) on Customer’s behalf; and (c) in compliance with Applicable U.S. Privacy Laws. Twingate certifies that it understands and will comply with the restrictions in this Section 9.

9.2. Restrictions. Twingate will:

(a) not retain, use, or disclose personal data outside of the direct business relationship between Customer and Twingate;

(b) not retain, use, or disclose personal data for any purpose, including any commercial purpose, other than the Purposes, unless expressly permitted by Applicable U.S. Privacy Laws;

(c) not Sell or Share any personal data (as such terms are defined in Applicable U.S. Privacy Laws) to any third party or process such personal data for Targeted Advertising purposes;

(d) comply with any applicable restrictions under the CCPA on combining personal data with personal data that Twingate receives from, or on behalf of, another source, or that Twingate collects from any interaction between it and any individual;

(e) provide the same level of protection for personal data subject to the CCPA as is required under the CCPA as applicable to Customer; and

(f) promptly notify Customer if Twingate determines that it can no longer meet its obligations under this Section 9 or Applicable U.S. Privacy Laws.

9.3. Customer Rights. To the extent that the CCPA applies, Customer retains the right to: (a) take reasonable steps to ensure that Twingate uses the personal data in a manner consistent with the CCPA; and (b) upon reasonable prior written notice, take reasonable and appropriate steps to stop and remediate unauthorized processing of personal data.

PART D: MISCELLANEOUS COMMON PROVISIONS

10. General Terms

10.1. Liability Toward Data Subjects. The parties’ liability will be governed by the liability provisions in the Agreement. However, each party agrees that it will be liable to data subjects for the entire damage resulting from a violation of European Data Protection Law. If one party paid full compensation for the damage suffered, it is entitled to claim back from the other party that part of the compensation corresponding to the other party’s part of responsibility for the damage. For that purpose, both parties agree that Customer will be liable to data subjects for the entire damage resulting from a violation of European Data Protection Law with regard to processing of personal data, and that Twingate will only be liable to data subjects for the entire damage resulting from a violation of the obligations of European Data Protection Law directed to Twingate or where it has acted outside of or contrary to Customer’s lawful instructions. Twingate will be exempt from liability if it proves that it is not in any way responsible for the event giving rise to the damage.

10.2. Applicable Law. This DPA and the processing of personal data under it are governed by the laws of the State of California, except where Applicable Data Protection Laws require this DPA to be governed by the laws of the jurisdiction in which Customer is established.

10.3. Modification. This DPA may only be modified by a written amendment signed by each of the parties.

10.4. Invalidity and Severability. If any provision of this DPA is found by any court or administrative body of competent jurisdiction to be invalid or unenforceable, the invalidity or unenforceability of such provision shall not affect any other provision of this DPA and all provisions not affected by such invalidity or unenforceability will remain in full force and effect.

10.5. Term. This DPA continues until the earlier of: (a) the expiry of Customer’s entitlement to use and receive the Services, as set forth in the Agreement, and (b) the termination of the Agreement.

10.6. Liability. In no event shall Twingate’s liability to Customer in connection with any issue arising out of, or in connection with, this DPA exceed Twingate’s limitations on liability set out in the Agreement. Twingate’s limitations on liability as set out in the Agreement shall apply in aggregate across both the Agreement and this DPA, such that a single limitation on liability regime shall apply across both the Agreement and this DPA.

* * *

Annex 1: Description of the processing

This Annex 1 describes the processing that Twingate will perform on behalf of Customer.

A. LIST OF PARTIES

Data exporter:

Name: Customer.

Contact details: The email address under which any of Customer’s Admin Accounts is registered.

Activities relevant to the data transferred under these clauses: The receipt of the Services provided by Twingate pursuant to the Agreement.

Signature and date: These Standard Contractual Clauses shall be deemed executed by Customer upon execution or acceptance of the Agreement.

Role (controller/processor): Controller or processor, depending on the circumstances (see Section 2 of this DPA).

Data importer:

Name: Twingate Inc.

Contact details: Twingate Privacy Team, privacy@twingate.com, 541 Jefferson Ave, Suite 100, Redwood City, CA 94063, USA.

Activities relevant to the data transferred under these clauses: The provision of the Services by Twingate pursuant to the Agreement. In general, Twingate provides services that are designed to enable Customer to manage, secure, and monitor access to systems, networks, devices, files, and other assets operated and made available by Customer.

Signature and date: These Standard Contractual Clauses shall be deemed executed by Twingate upon execution or acceptance of the Agreement.

Role (controller/processor): Processor.

B. DESCRIPTION OF TRANSFER

Categories of data subjects whose personal data is transferred: Customer may submit personal data to the Services, the extent of which is determined and controlled by Customer and may include, without limitation, personal data relating to the following categories of data subjects:

  • Employees, agents, advisors, contractors of Customer (and applicable Controllers, if Customer is a Processor) who are natural persons;

  • Employees or contact persons of Customer’s (and applicable Controllers’, if Customer is a Processor) business partners and vendors;

  • Customer’s end users who are authorized by Customer to use the Services.

Categories of personal data transferred: Customer may submit personal data to the Services, the extent of which is determined and controlled by the Customer and may include, without limitation, the following categories of personal data: name, email address, professional life data (e.g. job titles, department membership), device identifiers, network identifiers, network access activity, and localization data.

Sensitive data transferred (if applicable) and applied restrictions or safeguards that fully take into consideration the nature of the data and the risks involved, such as for instance strict purpose limitation, access restrictions (including access only for staff having followed specialised training), keeping a record of access to the data, restrictions for onward transfers or additional security measures: None.

The frequency of the transfer (e.g. whether the data is transferred on a one-off or continuous basis): Continuous throughout the duration of the Agreement.

Nature of the processing: The provision of the Services by Twingate to Customer pursuant to the Agreement.

Purpose(s) of the data transfer and further processing ("Purposes"): Customer will transfer personal data to Twingate for Twingate to provide the Services pursuant to the Agreement.

The period for which the personal data will be retained, or, if that is not possible, the criteria used to determine that period: Twingate will process personal data for the duration of the Agreement, unless otherwise agreed upon in writing.

For transfers to (sub-)processors, also specify subject matter, nature and duration of the processing: As described above and in the Agreement.

C. COMPETENT SUPERVISORY AUTHORITY

Identify the competent supervisory authority/ies (e.g. in accordance with Clause 13 of the Standard Contractual Clauses): The competent supervisory authority shall be determined in accordance with Clause 13 of the Standard Contractual Clauses, and to the extent legally permissible, shall be the Irish Data Protection Commission.

* * *

Annex 2: Technical and Organizational Measures

Description of the technical and organizational measures implemented by the processor(s)/data importer(s) (including any relevant certifications) to ensure an appropriate level of security, taking into account the nature, scope, context and purpose of the processing, and the risks for the rights and freedoms of natural persons.

Twingate’s technical and organizational security measures are described at https://www.twingate.com/docs/twingate-security/ and shall be deemed incorporated into these Standard Contractual Clauses. Twingate shall not modify these measures in a way that may adversely reduce the security of personal data it processes.

For transfers to Subprocessors, also describe the specific technical and organizational measures to be taken by the Subprocessor to be able to provide assistance to the controller (and, for transfers from a processor to a Subprocessor, to the data exporter).

When Twingate engages a subprocessor pursuant to this DPA, Twingate and the subprocessor enter into an agreement with applicable data protection obligations substantially similar to those contained in this DPA. Each subprocessor agreement must ensure that Twingate is able to meet its obligations to Customer. In addition to implementing technical and organizational measures to protect personal data, subprocessors must: (a) notify Twingate in the event of a Personal Data Breach so Twingate may notify Customer; (b) delete personal data when instructed by Twingate in accordance with Customer’s instructions to Twingate; (c) not engage additional subprocessors without Twingate’s authorization; and (d) not process personal data in a manner which conflicts with Customer’s instructions to Twingate.

* * *

Archived Versions