Data Transfers Addendum

Last updated: 7 January 2025

1. Introduction

This Data Transfers Addendum is incorporated by reference into the Data Processing Addendum (DPA) between you and Andri.ai, which governs Andri.ai's and its Affiliates' Processing of Personal Data. You may be referred to as "You" or "Customer" in your Andri.ai Platform Agreement, or any other agreement governing your use of Andri.ai's services. Any capitalized terms not defined in this Data Transfers Addendum have the meanings given in the DPA or Agreement.

2. Order of Precedence

If multiple Data Transfer Mechanisms could apply to a transfer of Personal Data, the transfer will be subject to one Data Transfer Mechanism only, according to the following order of precedence:

3. The EU Standard Contractual Clauses

Module 2 (Controller to Processor) of the EU SCCs applies to any transfer of Personal Data from the European Economic Area (EEA) to Andri.ai in a third country.

3.1 Purpose and Effect

These Clauses set out appropriate safeguards, including enforceable data subject rights and effective legal remedies, pursuant to Article 46(1) and Article 46(2)(c) of Regulation (EU) 2016/679.

3.2 Interpretation

3.3 Hierarchy

These Clauses prevail over any other agreements between the parties relating to data transfers.

3.4 Data Protection Safeguards

3.5 Duration and Data Return/Deletion

Processing occurs only for the duration specified. After services end, all personal data is deleted or returned, unless legal retention requirements apply.

4. UK International Data Transfer Addendum

4.1 Parties

Data Exporter:

Data Importer:

4.2 Governing Law

The Addendum is governed by the laws of England and Wales. Disputes are resolved by the courts of England and Wales.

5. Data Subject Rights

6. Details of the Transfer

6.1 Categories of Data Subjects

6.2 Categories of Personal Data

6.3 Special Categories of Data

Any sensitive data (including legal case details) is processed with additional safeguards and only when strictly necessary for the provision of services.

6.4 Processing Operations

7. Technical and Organizational Measures

7.1 Security Measures

7.2 Access Control

8. Sub-processor Management

9. Data Breach Notification

10. Audit Rights

11. Liability and Indemnification

Each party is liable for damages caused by breaching these clauses. The data importer is liable to data subjects for damages caused by breaching third-party beneficiary rights.

12. Termination

Data transfers may be suspended or terminated for breach of these clauses. All personal data must be returned or deleted upon termination.

13. Contact Information