1. Scope and application
This Addendum will apply, if required by Data Protection Legislation (as defined below) and only to the extent that, in providing any Alibaba Cloud Services to You, Alibaba Cloud processes as a processor personal data contained in or generated in relation to Your Member Content (the “Data”).
This Addendum forms part of Your Membership Agreement and capitalised terms not defined herein will have the meaning given in the Membership Agreement. In the event and to the extent of a conflict between the other terms of the Membership Agreement including its Addenda or any other agreements between You and Alibaba Cloud regarding the Data and this Addendum, this Addendum will prevail.
In this Addendum:
“controller”, “data subject”, “personal data”, “process”, “processor” and “supervisory authority” each has the meaning given in the GDPR.
“Data Protection Legislation” means, as applicable: (i) GDPR, and in each case, any related national laws, legislation, rules or regulations, related to privacy and data protection (including legislation made under or in relation to (i)). For clarity, a reference to Data Protection Legislation, includes a reference to Data Protection Legislation as amended, modified, extended, re-enacted, consolidated or replaced from time to time.
“GDPR” means Regulation (EU) 2016/679.
“Standard Contractual Clauses” means the standard contractual clauses annexed to the European Commission's Implementing Decision 2021/914/EU of 4 June 2021 on standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council (or any subsequent decisions) or as referred to in Article 46 GDPR.
3. Description of processing
For the purposes of this Addendum, You (the controller or processor) appoint Alibaba Cloud as Your processor to process the Data, for the duration of the Membership Agreement, for the purpose of providing the Alibaba Cloud Services to You (the “Permitted Purpose”).
4. Data processing
In processing the Data under this Agreement, Alibaba Cloud shall:
(a) only process the Data on Your documented instructions unless required otherwise by applicable law;
(b) ensure that all personnel authorised by Alibaba Cloud to process the Data are subject to suitable confidentiality obligations;
(c) implement and maintain appropriate technical and organisational measures as described at https://www.alibabacloud.com/trust-center, designed to protect the Data processed by Alibaba Cloud against a personal data breach affecting such Data arising from a breach of Alibaba Cloud’s security (a “Security Incident”). Alibaba Cloud may change those measures from time to time, but not so as to reduce the level of protection for Data. In the event of a confirmed Security Incident, Alibaba Cloud shall notify You without undue delay and shall provide reasonable information and cooperation to You so that You can fulfil any data breach reporting obligations You may have under (and in accordance with the timescales required by) applicable Data Protection Legislation. Alibaba Cloud shall further take any reasonably necessary measures and reasonably necessary actions to remedy or mitigate the effects of the Security Incident, and shall keep You informed of all material developments in connection with the Security Incident;
(d) be generally authorised to engage third party subcontractors to process the Data for the Permitted Purpose, provided that Alibaba Cloud (i) shall remain fully liable for any of its subcontractors; (ii) shall maintain an up-to-date list of such subcontractors here (accessible when You login to your Alibaba Cloud account), which it shall update with details of any change in such subcontractors at least 10 days’ before any such change; and (iii) shall impose data protection terms on any subcontractor it appoints to process any Data, that require it to protect such Data to at least the standard required by applicable Data Protection Legislation. You may object to Alibaba Cloud’s appointment or replacement of such a subcontractor before its appointment or replacement, provided such objection is based on reasonable grounds relating to data protection. In such event, Alibaba Cloud will either not appoint or replace the relevant subcontractor or, if this is not possible, You may terminate the relevant Service and this Addendum to the extent it applies to that Service, but without prejudice to any fees or costs incurred by You for that Service before that termination and without prejudice to the Membership Agreement, any other Services provided to You, and any fees or costs in relation to those other Services;
(e) assist You to respond to data subjects’ requests to exercise their rights regarding any Data under applicable Data Protection Legislation by providing You with technical measures to enable You, to the extent consistent with the functionality of the Alibaba Cloud Services and Alibaba Cloud’s role as a processor, to access, rectify, erase, restrict or export Data directly (and You agree that, taking into account the nature of the processing, this paragraph reflects the extent to which it is possible for Alibaba Cloud to provide You with such assistance). If a data subject, supervisory authority or any other party directly approaches Alibaba Cloud with any request, query or complaint regarding any Data, Alibaba Cloud shall, promptly notify You accordingly or notify that person that they should approach You instead;
(f) If Alibaba Cloud believes or becomes aware that its processing of the Data is likely to result in a high risk to the data protection rights and freedoms of data subjects, promptly inform You and provide reasonable cooperation to You (at Your expense) in connection with any data protection impact assessment that You may be required under applicable Data Protection Legislation to undertake for Your use of Alibaba Cloud Services;
(g) at Your choice, delete or return all Data in Alibaba Cloud’s possession or control following the termination of the Membership Agreement. This requirement shall not apply to the extent that Alibaba Cloud is required or permitted by applicable law to retain some or all of the Data, or Data archived on back-up systems, in which event Alibaba Cloud shall securely isolate and protect such Data from any further processing except to the extent required by such law until deletion is possible; and
(h) use independent qualified third party security professionals and auditors, at Alibaba Cloud’s selection and expense, to (at appropriate regular intervals) verify the adequacy of its security measures, including the security of the data centers from which Alibaba Cloud provides the Alibaba Cloud Services, and generating audit reports and certifications thereof (“Report and Certification”). You acknowledge that Alibaba Cloud is regularly audited against many industry-recognised standards by independent third party auditors as described at https://www.alibabacloud.com/trust-center. Upon Your written request, and subject to Your execution of a non-disclosure agreement covering the Report and Certification (and verification that you are not a competitor of Alibaba Cloud), Alibaba Cloud will make available to you a summary copy of the Report and Certification demonstrating Alibaba Cloud’s compliance with the obligations set forth in this Addendum.
If the Standard Contractual Clauses apply to You, then You agree to exercise Your audit right by instructing Alibaba Cloud to execute the audit as described in this section. If You desire to change this instruction, then You have the right to do so as set forth in the Standard Contractual Clauses which change shall be requested in writing (for clarity, nothing in the foregoing shall require Alibaba Cloud to make available any data, material or information of any of Alibaba Cloud’s other customers).
5. Your responsibilities
(a) To comply with your obligations under all applicable Data Protection Legislation in relation to Your use of Alibaba Cloud Services for processing any personal data comprised within the Data.
(b) That this Addendum, the Membership Agreement, Your other applicable agreements with Alibaba Cloud and Your configuration and use of the Alibaba Cloud Services will together comprise Your complete and final documented instructions to Alibaba Cloud on the processing of Data.
(c) That You shall not give Alibaba Cloud as Your processor any instructions, nor shall You use the Alibaba Cloud Services in any way, that in any such case could infringe any Applicable Data Protection Legislation or could cause Alibaba Cloud or any of its affiliates to infringe any Applicable Data Protection Legislation.
6. International transfers
6.1 If the processing of Data involves transfers out of the EEA, Alibaba Cloud will take such measures as are necessary to ensure the transfer is in compliance with applicable Data Protection Legislation. Such measures may include (without limitation) transferring the Data to a recipient in a country that the European Commission has decided provides adequate protection for personal data, to a recipient that has achieved binding corporate rules authorisation in accordance with applicable Data Protection Legislation, or to a recipient that has executed Standard Contractual Clauses together with any supplementary measures that may be necessary.
6.2 You agree that the Standard Contractual Clauses shall apply to any such transfers of the Data protected by the GDPR to Alibaba Cloud, except where Alibaba Cloud or its affiliates has provided any of the other measures as described above.
6.3 Such transfers to Alibaba Cloud shall be subject to the appropriate Standard Contractual Clauses as follows:
(a) If and to the extent You are a controller of such Data Module Two will apply, and if and to the extent You are a processor of such Data Module Three will apply, in each case as follows:
(i) in Clause 7, the optional docking clause will apply (provided that any new party to the Standard Contractual Clauses shall be subject to Alibaba Cloud's prior written agreement);
(ii) in Clause 9, Option 2 will apply, and the time period for prior notice of subcontractor changes shall be as set out in Clause 4(d) of this Addendum.
(iv) in Clause 11, the optional language will not apply;
(v) in Clause 17, Option 1 will apply and the Standard Contractual Clauses will be governed by Dutch law;
(vi) in Clause 18(b) disputes shall be resolved before the courts of the Netherlands;
(vii) Annex I of the Standard Contractual Clauses shall be deemed completed with the information set out in this Addendum and/or in the Appendix 1 to this Addendum, and the competent supervisory authority under Part C of Annex I shall be determined in accordance with Clause 13 of the Standard Contractual Clauses;
(viii) Annex II of the Standard Contractual Clauses shall be deemed completed with the information set out in the document linked to in Clause 4(c) of this Addendum;
(b) The following clarifications shall apply to the Standard Contractual Clauses:
(i) You may exercise your right of audit under the Standard Contractual Clauses as set out in and subject to the requirements, of Clause 4(h) of this Addendum;
(ii) Alibaba Cloud may appoint subcontractors as set out in and subject to the requirements of Clause 4(d) of this Addendum and You may exercise your right to reject to subcontractors under the Standard Contractual Clauses in the manner set out in Clause 4(d) of this Addendum;
(iii) Clause 4(g) shall apply in relation to the deletion or return of transferred Data on any termination of the Membership Agreement;
(iv) For the avoidance of doubt, in light of the nature of the Alibaba Cloud Services You are solely responsible for the accuracy of the Data and the legality of its collection by You, and Alibaba Cloud is not obliged to check any transferred Data for accuracy;
(c) You will pay Alibaba Cloud fees at its then standard professional services rates and also reimburse Alibaba Cloud for its reasonable costs reasonably incurred in dealing with any inquiries from you relating to any transferred Data and/or for providing You with any assistance requested by You under the Standard Contractual Clauses, including without limitation for notifying or otherwise assisting You with data subject requests or responses to data subjects, and cooperation with You to erase or rectify any transferred Data; and
(d) In the event that any provision of this Addendum contradicts, directly or indirectly, the Standard Contractual Clauses, the Standard Contractual Clauses shall prevail.
(a) For clarity, the total aggregate liability of Alibaba Cloud and all its affiliates, employees, agents, affiliates, representatives or anyone acting on its behalf together, arising from or in connection with the Membership Agreement and/or this Addendum and/or the Standard Contractual Clauses or any matter arising therefrom shall not exceed the maximum liability of Alibaba Cloud as limited by the paragraph following Clause 11.5 of the Membership Agreement.
(b) Alibaba Cloud may modify the terms of this Addendum, for example to comply with applicable law or to implement any standard contractual clauses adopted by the European Commission or a supervisory authority under Article 28 of the GDPR, but it will not do so in a way that would reduce the protections required to be afforded to You under Article 28 of the GDPR. If it does so, it an amended and restated version on the Alibaba Cloud Platform, providing at least 15 days prior written notice of any material amendments to the Addendum to You (which may be posted on the Alibaba Cloud Platform or displayed in your Alibaba Cloud account). By continuing to use the relevant products or services after the receipt of written notification of such changes by Alibaba Cloud, you agree to be bound by the amended and restated Addendum.
Data exporter name, address and contact person’s name, position and contact details
Name: The entity identified as “Customer” in the Membership Agreement.
Address: The address for Customer associated with its Alibaba Cloud account or as otherwise specified in this Data Processing Addendum or the Membership Agreement.
Contact person’s name, position and contact details: The contact details associated with Customer’s account, or as otherwise specified in this Data Processing Addendum or the Membership Agreement.
Activities relevant to the data transferred under these Clauses: The activities specified in Section 4 of this Data Processing Addendum.
Signature and date: By using the Alibaba Cloud services to transfer Member Content to third countries, the data exporter will be deemed to have signed this Annex I.
Role (controller / processor): Exporter as controller or processor, as set out in Section 6.3 (a) of this Data Processing Addendum
Name: "Alibaba Cloud” as identified in the Membership Agreement.
Address: The address for Alibaba Cloud specified in the Membership Agreement.
Contact person’s name, position and contact details: The contact details for Alibaba Cloud specified in the Addendum or the Membership Agreement.
Activities relevant to the data transferred under these Clauses: The activities specified in Section 4 of this Data Processing Addendum.
Signature and date: By transferring Member Content to third countries on Customer’s instructions, the data importer will be deemed to have signed this Appendix 1.
Role (controller / processor): Importer as Processor.
Data subjects The data subjects may include Your customers, employees, supplier and end-users.
Categories of data Capitalised terms not defined herein will have the meaning given in Your Membership Agreement with Alibaba Cloud.The personal data includes any information, content, material and data in electronic format as may be contained in or generated in relation to Member Content.
You may upload special categories of personal data to Your Alibaba Cloud Services at Your sole choice, which could include (depending on Your choice) personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person's sex life or sexual orientation, and/or personal data relating to criminal convictions and offences or related security measures. Before uploading any sensitive data, You are obliged to assess and confirm that the technical and organizational measures taken by Alibaba Cloud are sufficient for the sensitive data that You choose to upload.
Processing operations, subject matter and nature of the processing, purpose of the transfer and any further processing, and activities relevant to any Data transferred under the Standard Contractual Clauses The personal data will be processed and transferred for the purposes of providing You with the Services and as otherwise set out in the Agreement.
The frequency of the transfer (e.g. whether the data is transferred on a one-off or continuous basis)
Data may be transferred on an occasional or continuous basis solely for the purposes of providing You with the Services and as otherwise set out in the Agreement.
Duration of processing, period for which the personal data will be retained
Data will be processed and transferred for the duration of the Agreement.