This Data Transfer Addendum (“Transfer Addendum”) supplements the Legasus Data Processing Addendum (“DPA”) between AIDAN LLC d/b/a Legasus (“Legasus”) and Customer. It applies to Restricted Transfers of Customer Personal Data that require an approved transfer mechanism under Applicable Data Protection Law.
Capitalized terms not defined here have the meanings in the DPA or Agreement.
1. Purpose
Legasus is a United States company and Customer Data is primarily hosted in the United States unless otherwise stated in an Order Form or written configuration. This Transfer Addendum establishes contractual safeguards for Customer Personal Data transferred from jurisdictions that restrict international transfers.
2. Transfer Mechanism Hierarchy
A Restricted Transfer will use the first lawful mechanism available in the following order, to the extent applicable:
- an applicable adequacy decision, regulation, or statutory transfer mechanism recognized by the relevant jurisdiction;
- another valid transfer mechanism expressly agreed by the parties and recognized by applicable law;
- for transfers subject to the EU GDPR, the European Commission Standard Contractual Clauses described in Section 3;
- for transfers subject to the UK GDPR, the UK transfer mechanism described in Section 4; and
- for Swiss transfers, the mechanism and adaptations described in Section 5.
If the law changes or a mechanism becomes invalid, the parties will cooperate in good faith to implement an alternative lawful mechanism.
3. European Economic Area — Standard Contractual Clauses
3.1 Incorporation
For a Restricted Transfer governed by the EU GDPR that is not otherwise covered by a valid adequacy or other lawful mechanism, the parties incorporate the European Commission's Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 of 4 June 2021 (“EU SCCs”).
3.2 Applicable Module
The applicable module will be determined by the parties' roles:
- Module Two (Controller to Processor) applies where Customer is a controller and Legasus is a processor.
- Module Three (Processor to Processor) applies where Customer is a processor acting on behalf of another controller and Legasus is Customer's subprocessor.
Other modules apply only if the parties expressly agree and the factual roles require them.
3.3 Optional Clauses
Where permitted by the applicable module:
- the optional docking clause is deemed included;
- general written authorization for subprocessors applies as described in the DPA;
- the notice period for intended subprocessor changes will be the notice required by the DPA and applicable law rather than a fixed universal period; and
- no optional redress body is designated unless the parties agree otherwise.
3.4 Clause 7 — Docking
The docking clause is included to permit additional eligible entities to accede where the requirements of the EU SCCs are satisfied.
3.5 Clause 9 — Subprocessors
Option 2, general written authorization, applies. Legasus will maintain a Subprocessor List and provide notice of intended changes where required as described in the DPA.
3.6 Clause 11 — Redress
The optional language in Clause 11 is not selected unless required by law or agreed in writing.
3.7 Clause 13 — Supervisory Authority
The competent supervisory authority will be determined under Clause 13 of the EU SCCs based on the Data Exporter's establishment, representative, or relevant Data Subjects and Applicable Data Protection Law.
3.8 Clause 17 — Governing Law
The EU SCCs will be governed by the law of the EU Member State in which the Data Exporter is established where that law permits third-party beneficiary rights. If no such law can validly be selected, the parties select the law of Ireland solely for purposes of Clause 17 of the EU SCCs.
3.9 Clause 18 — Courts
The courts identified under Clause 18 of the EU SCCs will be the courts of the Member State whose law applies under Clause 17. If Irish law applies under Section 3.8, the courts of Ireland are selected solely for the EU SCCs.
3.10 Annex I.A — Parties
Data Exporter: Customer and, where applicable, Customer's relevant affiliates identified in an Order Form or that lawfully use the Services under the Agreement. Customer's contact details are those in the applicable Order Form/account records.
Data Importer: AIDAN LLC d/b/a Legasus, United States. Privacy contact: privacy@legasus.ai.
Activities relevant to the transfer are described in the Agreement and DPA.
3.11 Annex I.B — Description of Transfer
The categories of Data Subjects, Personal Data, sensitive data, frequency, nature, purpose, retention, and Processing are described in Annex I of the DPA and are incorporated here.
3.12 Annex I.C — Supervisory Authority
The competent supervisory authority is determined under Section 3.7.
3.13 Annex II — Technical and Organizational Measures
The Legasus Security Addendum is incorporated as Annex II to the EU SCCs.
3.14 Annex III — Subprocessors
The current Legasus Subprocessor List is incorporated as Annex III where required.
4. United Kingdom Transfers
4.1 UK Mechanism
For a Restricted Transfer subject to the UK GDPR, the parties will use the then-current transfer mechanism recognized by the UK Information Commissioner's Office, which may include:
- the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses (“UK Addendum”); or
- the International Data Transfer Agreement (“IDTA”), where appropriate.
Unless the parties agree otherwise, where the EU SCCs also apply to the same processing relationship, the parties incorporate the UK Addendum so the EU SCCs can serve as the underlying approved clauses for the UK Restricted Transfer.
4.2 UK Addendum Tables
To the extent the UK Addendum requires completion of tables:
- the parties and contact information are those identified in the Agreement, Order Form, DPA, and Section 3.10 above;
- the selected EU SCC modules are those specified in Section 3.2;
- Appendix information is supplied by the DPA, Security Addendum, and Subprocessor List; and
- either party may end the UK Addendum as permitted by its mandatory terms if the approved mechanism materially changes and a replacement lawful mechanism is implemented.
4.3 Mandatory UK Terms
Nothing in this Transfer Addendum varies mandatory provisions of the applicable UK Addendum or IDTA. If there is a conflict, the mandatory UK terms control for the relevant Restricted Transfer.
5. Switzerland
For Personal Data protected by the Swiss Federal Act on Data Protection (“FADP”) that is transferred internationally using the EU SCCs:
- references to the GDPR will be interpreted, where appropriate, to include the FADP;
- references to EU/Member State law will be interpreted to include applicable Swiss law where necessary;
- the term “personal data” includes personal data protected under the FADP;
- the competent supervisory authority for FADP matters will be the Swiss Federal Data Protection and Information Commissioner where required; and
- Data Subjects in Switzerland may enforce rights granted to them under the applicable transfer mechanism and Swiss law.
If the Swiss authority requires different or additional modifications, those mandatory requirements will control.
6. Transfer Impact Assessments and Supplementary Measures
Taking into account the nature of Processing and information available to Legasus, the parties will reasonably cooperate with assessments required by Applicable Data Protection Law concerning government access, transfer risks, and supplementary measures.
Legasus may provide relevant information through standard security/privacy documentation rather than disclosing sensitive security details publicly.
Legasus may implement supplementary measures such as encryption, access control, minimization, contractual restrictions, transfer limitations, security monitoring, or other reasonable measures appropriate to the Processing.
7. Government Access Requests
Legasus's obligations regarding governmental requests are described in the DPA and MSA. To the extent required by applicable transfer law, Legasus will use reasonable efforts to review the legality and proportionality of governmental demands and challenge unlawful or overbroad demands where appropriate and legally available.
8. Onward Transfers
Legasus will permit onward transfers of Customer Personal Data only where authorized under the DPA and where appropriate contractual or legal safeguards apply.
Subprocessors receiving restricted-transfer data will be subject to appropriate transfer mechanisms where required.
9. Conflict
If this Transfer Addendum conflicts with mandatory terms of the EU SCCs, UK Addendum/IDTA, or other legally required transfer mechanism, the mandatory transfer mechanism controls solely with respect to the Restricted Transfer.
Otherwise, the DPA's order-of-precedence provisions apply.
10. Changes in Law
If a transfer mechanism is amended, replaced, invalidated, or no longer reasonably available, Legasus may update this Transfer Addendum to incorporate a successor mechanism or other lawful safeguard. The parties will take reasonably necessary steps to preserve lawful transfers.
11. Contact
Privacy and transfer inquiries: privacy@legasus.ai
Legal: legal@legasus.ai