Data Processing Addendum

The data protection terms that apply when Birdie processes personal data on behalf of a customer.

This Data Processing Agreement forms an addendum to the Terms of Use between Birdie and Customer for the purchase of Services, including any and all applicable Order Form(s), Purchases, exhibits and/or schedules (the “Agreement”).

In the course of providing the Services to Customer pursuant to the Agreement, Birdie may Process Personal Data on behalf of Customer. This DPA reflects the parties’ agreement with regard to the Processing of Personal Data.

The Parties agree to comply with the following provisions with respect to any Personal Data, each acting reasonably and in good faith.

Definitions

All capitalized terms not defined herein shall have the meaning ascribed to them in the Agreement. In this DPA, the following capitalized terms used shall further have the meanings given to them below:

The terms “Data Controller” and “Data Processor” shall have the meaning ascribed by the GDPR. The terms “Data Subject”, “Personal Data” and “Process, Processing” shall have the meaning ascribed by the GDPR, but shall only cover the scope of personal data processing specified in Exhibit A of this DPA. However, in case that the Applicable Data Protection Laws define these terms differently and the GDPR does not apply to the Processing, the definition set forth by the Applicable Data Protection Laws shall apply instead of the definition ascribed by the GDPR. In case that the Applicable Data Protection Laws define these terms differently and the GDPR applies to the Processing, the definition provided in the GDPR will prevail. Incase the Applicable Data Protection Laws define terms, which have the same or materially similar meaning to the terms “Data Controller”, “Data Processor”, “Data Subject”, “Personal Data”and/or “Process, Processing”, such terms will be considered as covered correspondingly by the definitions provided herein.

The terms “Business Associate Agreement”, “Covered Entity” and “Protected Health Information” shall have the meaning ascribed by HIPAA and shall be interpreted in accordance with relevant regulations issued by the U.S. Department of Health and Human Services.

“Admin User Email Address” means every email address associated with the Customer’s account with Birdie in the way that it is, at the given point of time, registered by Birdie as an email address of an admin user of the Customer’s account.

“Applicable Data Protection Laws” means all data protection laws and regulations applicable to the Processing of Personal Data under this DPA, which may, depending on the circumstances, include but not be limited to the European Data Protection Laws and/or HIPAA, as defined below.

“Data Breach” means a personal data breach concerning Personal Data, which is likely to result in a risk to the rights and freedoms of the Data Subjects.

“EEA” means the European Economic Area.

“EU GDPR” means Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC.

“European Data Protection Laws” means the GDPR and/or the FADP, as applicable to the Personal Data Processing in question.

“FADP” means the Federal Act on Data Protection adopted by the Federal Assembly of the Swiss Confederation, as amended.

“GDPR” means the EU GDPR and/or the UKGDPR, as applicable to the Personal Data Processing in question.

“HIPAA” means the United States’Health Insurance Portability and Accountability Act of 1996.

”EU Standard Contractual Clauses for Data Transfers to Third Countries” means the standard contractual clauses as approved by the European Commission’s decision 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of personal data to third countries pursuant to the EU GDPR, and any amendments thereto.

”Subprocessor” means any legal entity, including a subcontractor, engaged by Birdie to Process all or part of the Personal Data for Birdie on behalf of the Customer.

“UK GDPR” has the meaning given to it in section 3(10) of the UK Data Protection Act 2018.

“UK International Data Transfer Addendum”means the International Data Transfer Addendum to the EU Standard Contractual Clauses, issued by the Information Commissioner and laid before Parliament in accordance with s.119A of the UK’s Data Protection Act 2018 on 2 February 2022 and any amendments thereto.

1. Application of data protection laws and terms

Compliance with Applicable Data Protection Laws. The Customer hereby represents that this DPA complies, to its reasonable knowledge, with all Applicable Data Protection Laws and contains all provisions required by such laws. Considering the nature of the Services, the Customer acknowledges that the Processing of Personal Data under this DPA may be subject to various Applicable Data Protection Laws, even those which are not explicitly mentioned in this DPA, depending on the territorial extent of Customer’s usage of the Services. The Customer is responsible for informing Birdie without undue delay about any discrepancy between this DPA and the requirements of the Applicable Data Protection Laws.

Applicability of the European Data Protection Laws, roles of the Parties. The parties acknowledge that GDPR applies to the Processing of Personal Data if and to the extent conditions set forth by Art. 3 of the GDPR are fulfilled. The parties further acknowledge that the FADP applies to the Processing of Personal Data if and to the extent conditions set forth by the FADP are fulfilled. To the extent the European Data Protection Laws apply to the Processing of Personal Data under this DPA, the Customer may act as a Data Controller and/or a Data Processor and Birdie acts as a Data Processor. Where the Customer acts as a Data Processor and engages Birdie as another Data Processor in accordance with Art. 28(4) of the GDPR, the Customer:

a) Is responsible for ensuring that the same data protection obligations as set out in the contract or other legal act between the Customer and the Data Controller of the Personal Data are hereby imposed on Birdie;

b) Is responsible for ensuring that the instructions provided by the Customer to Birdie under Section 2.4 of this DPA do not violate the contract or other legal act between the Customer and the Data Controller of the Personal Data;

c) Assumes the rights and responsibilities of Data Controller towards Birdie under this DPA, therefore whenever this DPA refers to a “Data Controller”, such reference shall equally refer to the Customer, and vice versa;

Applicability of HIPAA. The Customer understands and agrees that it must separately enter into and execute a Business Associate Agreement (“BAA”) if (1) Customer qualifies asa Covered Entity or Business Associate and (2) Customer will make Protected Health Information available to Birdie in connection with performing the Agreement, to the extent such Protected Health Information is collected from patients in the United States and its territories and possessions. Where the parties have entered into a BAA, the BAA shall take precedence over this DPA with respect to any Protected Health Information collected from patients in the United States and its territories and possessions.

2. Processing of personal data

Customer’s Processing of Personal Data. Customer determines the purposes and means of the Processing of Personal Data. Customer’s instructions for the Processing of Personal Data shall comply with Applicable Data Protection Laws.

Customer’s liability. The Customer shall have sole responsibility for the accuracy, quality, and legality of Personal Data provided by the Customer to Birdie and the means by which Customer acquired such Personal Data. To the extent the European Data Protection Laws apply to the Processing of Personal Data under this DPA, the Customer is liable for complying with its obligations as Data Controller, including informing the Data Subjects about the Processing of their Personal Data under this DPA, obtaining their consent, if necessary, and ensuring that the Customer and Birdie have the authority to use the Personal Data in accordance with the purposes defined herein.

Customer’s Instructions. Customer instructs Birdie to Process Personal Data for the provision of Services, as specified in more detail in Exhibit A hereof. The Parties agree that this DPA, the Agreement, instructions provided via configuration tools incorporated in Birdie’s platform and instruction provided via Birdie’s dedicated customer support portal constitute Customer’s complete and final instructions to Birdie for the Processing of Personal Data. Any additional or alternate instructions must be agreed upon separately in writing.

Obligations of Birdie. To the extent set forth by the Applicable Data Protection Laws, Birdie agrees, warrants and represents that it:

a) Ensures that persons authorized to Process the Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality; further, Birdie shall only allow access to the Personal Data to such of the Birdie’s personnel who need access to the Personal Data in order to allow Birdie to perform its obligations under the Agreement;

b) Informs immediately the Customer if, to Birdie’s knowledge, an instruction infringes the Applicable Data Protection Laws;

c) Takes all measures to ensure the confidentiality of Personal Data and the security of Processing, as further specified in Section 3 hereof;

d) Assists the Customer in ensuring compliance with the obligations relating to the security of the Personal Data (as further specified in Section 3 hereof), Customer’s notification &communication obligations in case of Data Breach (as further specified in Section 7 hereof), conducting data protection impact assessments (or a similar assessment as designated by the Applicable Data Protection Laws) and consulting the supervisory authority if need be, taking into account the nature of Processing and the information available to Birdie; and

e) Makes available to the Customer on a reasonable basis all information necessary to demonstrate compliance with the obligations relating to Birdie as laid down in this DPA and in the Applicable Data Protection Laws, if applicable.

3. Security of Personal Data

Technical and Organizational Measures. Birdie shall, while taking into account the state of the art, the cost of implementation and the nature, scope, context and purposes of Processing as well as the risks of varying likelihood and severity for rights and freedoms of Data Subjects resulting from the Processing, implement appropriate technical and organizational measures listed in Exhibit B.

Reviews and Updates. The technical and organizational measures shall be reviewed and updated by Birdie where and when necessary. The Customer agrees that Birdie may unilaterally update the technical and organizational measures from time to time provided that such updates do not result in a material reduction of the level of protection of the Personal Data. Birdie’s obligation under Section 3.1 hereof remains unaffected.

Information. Birdie will provide the Customer with more information about securing, accessing and using Personal Data, anytime upon Customer’s request.

4. Rights of Data Subjects and Other Regulatory Actions

Data subjects’ right to information. It is the Customer’s responsibility to provide the Data Subjects with the information on the processing of their Personal Data.

Exercise of data subjects’ rights. To the extent set forth by the Applicable Data Protection Laws, Birdie shall assist the Customer, insofar as this is possible, for the fulfilment of its obligation to respond to Data Subject right requests concerning notably the right of access, to rectification, erasure and to object, right to restriction of processing, right to data portability, right not to be subject to an automated individual decision (including profiling).

Regulatory Action. If Birdie receives notice (whether or not from the Customer) of, any claim, complaint, request, direction, query, investigation, proceeding or other action of any Data Subject, court, regulatory or supervisory authority, or any body, organization or association in each case which relates in any way to the Personal Data Processed by Birdie under this DPA (collectively,“Regulatory Action”), then Birdie shall, if and to the extent required by the Applicable Data Protection Laws:

a) Notify the Customer via email sent to the Admin User Email Address with reasonable detail of the Regulatory Action,including copies of any relevant correspondence so that the Customer can deal with the Regulatory Action;

b) Provide the Customer with reasonable cooperation and assistance by appropriate technical and organizational measures with respect to any Regulatory Action; and

c) Not answer to a Regulatory Action, unless instructed otherwise by the Customer in writing or unless Birdie is required to answer under the Applicable Data Protection Laws.

5. Subprocessors

List of Subprocessors. Customer agrees that Birdie engages Subprocessors in connection with the provision of Birdie’s Services and that the list of the Subprocessors currently engaged by Birdie is listed on Birdie’s website. Therefore, by entering to this DPA, Customer authorizes Birdie to engage the Subprocessors mentioned in this list (https://birdie.so/privacy-policy#where-does-my-data-go-outside-of-birdie). Note that not all Subprocessors may be engaged, depending on the data storage location of your Birdie account.

General authorization. By executing the DPA, the Customer further grants Birdie with a general authorization to engage other Subprocessors, add or replace the Subprocessors in the list. In case the list of Subprocessors is modified by Birdie, Customer will be informed of any intended changes via email to the Admin User Email Address. This information will clearly indicate which processing activities are being subcontracted out, the name and contact details of the intended subprocessor.

Objections. To the extent Applicable Data Protection Laws grants Customer the right to object against intended modifications concerning the addition or replacement of the Subprocessors, the Customer may reasonably object to such modification. Incase Customer does not send any objection to Birdie in writing within thirty (30)days from receiving the information, it will be deemed to have agreed to the new Subprocessors. If Customer objects, the Parties agree to negotiate to find a solution that will satisfy both Parties’ interests.

Same obligations. Where Birdie engages another Subprocessor, it shall do so by way of a contract which imposes on the Subprocessor the same obligations as the ones imposed on Birdie under this DPA. Birdie shall ensure that the Subprocessor complies with the obligations to which the data processor is subject pursuant to this DPA and the Applicable Data Protection Laws.

Subprocessor agreements. To the extent required by the Applicable Data Protection Laws and permitted by Birdie’s confidentiality obligations, Birdie may provide, at the Customer’s request, a copy of such a Subprocessor agreement and subsequent amendments to the Customer.

Liability. To the extent set forth by the Applicable Data Protection Laws, Birdie shall be liable towards the Customer for the acts and omissions of its Subprocessors to the same extent Birdie would be directly liable if performing the Services of each Subprocessor directly under the terms of this DPA.

6. International Data Transfers

Locations of Processing. Birdie hereby represents that it will Process Personal Data under this DPA exclusively in the country of Birdie’s residence and in the countries designated in the list of Birdie’s Subprocessors maintained under Section 5.1hereof.

European Personal Data transfers subject to appropriate safeguards. The locations described is Section 6.1 herein above may include countries located outside the EEA, UK and Switzerland and, for the purposes of the applicable European Data Protection Law, (i) have not been recognized by the relevant authority as providing an adequate level of protection for personal data (as described in the applicable European Data Protection Law) or (ii) are not covered by a suitable framework recognized by the relevant authorities or courts as providing an adequate level of protection for personal data (“Locations Subject to Appropriate Safeguards”). Where the Processing of Personal Data is subject to the European Data Protection Law, the Parties shall not transfer Personal Data to any Location Subject to Appropriate Safeguards, unless the Parties have taken measures necessary to ensure that the transfer complies with the applicable European Data Protection Law.

EEA and Swiss Personal Data transfers to Birdie. Where the Processing of Personal Data consists of or includes a transfer of Personal Data from the Customer, whose activities are subject to the EU GDPR or the FADP, to Birdie, who is in a Location Subject to Appropriate Safeguards and whose activities are not subject to the EU GDPR or the FADP, the EU Standard Contractual Clauses for Data Transfers to Third Countries will apply and are hereby incorporated to this DPA. If necessary, Birdie shall apply supplementary measures to ensure that the Personal Data transferred hereunder receives an essentially equivalent protection as that guaranteed in its original jurisdiction. For the purposes of the EU Standard Contractual Clauses for Data Transfers to Third Countries hereunder:

a) The Customer acts as a data exporter and Birdie acts as a data importer;

b) Where the Customer acts as a Data Controller, Module 2: Transfer controller to processor will apply;

c) Where the Customer acts as a Data Processor, Module 3: Transfer processor to processor will apply;

d) Clause 7 – Optional - Docking clause, will apply;

e) In Clause 9 – Use of sub-processors, Option 2 will apply, and the period for prior notice of sub-processor changes shall be ten (10) business days;

f) In Clause 11 - Redress, the optional language will not apply;

g) In Clause 12 - Liability, any claims brought under the EU Standard Contractual Clauses for Data Transfers to Third Countries shall be subject to the terms and conditions set forth in this Agreement, whereby in no event shall any Party limit its liability with respect to any Data Subject rights under the EU Standard Contractual Clauses for Data Transfers to Third Countries;

h) In Clause 17 – Governing law, Option 1will apply, the clauses will be governed by the laws of France;

i) In Clause 18(b) - Choice of forum and jurisdiction, disputes shall be resolved before the courts of France;

j) Annex I(a) – List of Parties, shall be deemed completed with the following information:

i) The names and addresses of the data exporter and the data importer: as identified in the Agreement;

ii) The contact details of the data importer: privacy@birdie.so;

iii) The contact details of the data exporter: the Admin User Email Address;

iv) Activities relevant to the data transferred under these Clauses: identified in the list of Subprocessors (Section 5.1 of the DPA);

v) Signature and date: detailed in the Agreement;

k) Annex I(b) – Description of Transfer, shall be deemed completed with the following information:

i) Categories of data subjects whose personal data is transferred, purpose(s) of the data transfer and further processing and the period for which the personal data will be retained:detailed in Exhibit A of the DPA;

ii) Categories of personal data transferred: detailed in Exhibit A of the DPA;

iii) The frequency of the transfer:Personal data is transferred on a continuous basis;

iv) Subject matter, nature and duration of the processing or transfers to subprocessors: identified in the list of Subprocessors (Section 5.1 of the DPA);

v) Signature and date: detailed in the Agreement;

l) For the purposes of Annex I(c) –Competent Supervisory Authority, the competent supervisory authority in accordance with Clause 13 of the EU Standard Contractual Clauses for Data Transfers is the Commission nationale de l’informatique et des libertés (CNIL);

m) Annex II – Technical and Organizational Measures including Technical and Organizational Measures to Ensure the Security of the Data, shall be deemed completed with the information inserted in Exhibit B of this DPA; and

n) For the purposes of Annex III - List of Sub-processors, the data exporter has authorised the use of the Subprocessors detailed in Section 5.1 of the DPA and the list of Subprocessors referred to therein.

UK Personal Data transfers to Birdie. Where the Processing of Personal Data consists of or includes a transfer of Personal Data from the Customer, whose activities are subject to the UK GDPR, to Birdie, who is in a Location Subject to Appropriate Safeguards and whose activities are not subject to the UK GDPR, the UK International Data Transfer Addendum will apply. As permitted by clause 17 of such addendum, the Parties agree to change the format of the information set out in Part 1 of the addendum so that:

a) The details of the Parties in table 1shall be deemed completed with the information inserted or referenced in the Agreement, including the references in Section 6.3 of this DPA;

b) For the purposes of table 2, the UK International Data Transfer Addendum shall be deemed appended to the EU Standard Contractual Clauses for Data Transfers as defined in Section 6.3 of this DPA (including the selection of modules and options and the disapplication of optional clauses as defined in Section 6.3 of this DPA);

c) The appendix information listed in table 3 shall be deemed completed with the information inserted or referenced in Section 6.3 hereof; and

d) For the purposes of table 4, either the data importer or data exporter may end this addendum as set out in clause 19 of the Addendum.

European Personal Data onward transfers. Where the Processing of Personal Data consists of or includes a transfer of Personal Data from Birdie, whose activities are subject to the European Data protection Law, acting as a data exporter, to a third party, who is in a Location Subject to Appropriate Safeguards and whose activities are not subject to the European Data protection Law, acting as a data importer(including, but not limited to, the Subprocessors), Birdie may transfer the Personal Data to the third party only if conditions of Section 6.2 hereof are met.

Conflict. In the event of any conflict or inconsistency between this DPA and the EU Standard Contract Clauses for Data Transfers to Third Countries incorporated herein, the EU Standard Contractual Clauses for Data Transfers to Third Countries shall prevail.

7. Data Breaches

Notification. Birdie will notify Customer of any Data Breach promptly after detection of such Data Breach by Birdie. Where a European Data Protection Law applies, Birdie will notify Customer no later than 24 hours after such detection. The notification shall be carried out via email sent to Admin User Email Address.

Provided information. Birdie undertakes to provide the Customer with all reasonable cooperation and assistance, as well as all details of the Data Breach required for the Customer to comply with its obligations under the Applicable Data Protection Laws in relation to the Data Breach.

8. Audit rights

Customer audit right. If and to the extent such right is granted to the Customer by the Applicable Data Protection Laws, Customer or its independent third party auditor reasonably acceptable to Birdie (which shall not include any third party auditors who are either a competitor of Birdie or not suitably qualified or independent) may audit practices relevant to Personal Data Processing by Birdie, if:

a) The Customer has reasonable grounds, proved in advance to Birdie, to believe that Birdie does not Process Personal Data in compliance with this DPA or the Applicable Data Protection Laws or that a Data Breach has occurred; or

b) The audit is formally requested by Customer’s data protection authority; or

c) Applicable Data Protection Laws provide Customer with a direct audit right.

Audit frequency. The Customer shall conduct the audit at maximum once in any twelve month period, unless Applicable Data Protection Laws require more frequent audits.

Cost of Audits. Each Party shall bear its costs of audits hereunder.

9. Return and deletion of customer’s data

Return (export) right and deletion. Upon the termination of the Agreement, Birdie will permit the Customer to export the Personal Data Processed under this DPA, at its expense, in accordance with the capabilities of the Service, within the period of thirty (30) days following such termination. After the expiry of such period, Birdie will delete all Personal Data stored or Processed by Birdie exclusively on behalf of the Customer and their copies, unless an applicable law requires storage of the personal data. The Customer expressly consents to such deletion and acknowledges that following the period stated in the first sentence of this Section, Birdie shall not be able to facilitate any export of the Personal Data to the Customer, as such Personal Data shall be either deleted or archived by Birdie as a Data Controller for the purpose(s) and for the period(s) stated in Birdie’s Privacy Policy.

10. Terms and Amendments

Commencement and previous agreements. This DPA becomes effective the date on which Customer accepted this DPA and replaces, as of the same date, any previously applicable data processing terms.

Duration. This DPA will remain in force as long as the Agreement.

Amendments. The customer explicitly acknowledges and agrees that this DPA may be amended in the same way as agreed by the parties for amendments of the Agreement, including Birdie’s right to update the terms of the Agreement, any of its policies and this DPA from time to time, as decided by Birdie in its sole discretion, subject to notice to Customer at the Admin User Email Address.

11. Liability

Birdie’s aggregate liability. Each party’s and all of its Affiliates’ liability, taken together in the aggregate, arising out of or related to this DPA, and all DPAs between Affiliates and Birdie, whether in contract, tort (including negligence) or under any other theory of liability, is subject to the ‘Limitation of Liability’ section of the Agreement (or the section of the Agreement which addresses the exclusion and limitation of liability even if it does not have that heading), and any reference in such section to the liability of a party means the aggregate liability of that party and all of its Affiliates under the Agreement and all DPAs together.

Liability towards Customer’s Affiliates. For the avoidance of doubt, Birdie and its Affiliates’ total liability for all claims from Customer and all of its Affiliates arising out of or related to the Agreement and all Data Processing Agreements whether in contract, tort (including negligence) or under any other theory of liability shall apply in the aggregate for all claims under both the Agreement and the Data Processing Agreements established under the Agreement or otherwise concluded between Birdie and the Customer and/or any Affiliate, and, in particular, shall not be understood to apply individually and severally to Customer and/or to any Affiliate that is a contractual party to, or otherwise entitled to claim under, any such Data Processing Agreement.

12. Governing Law and Jurisdiction

Governing law. Without prejudice to mandatory application of Applicable Data Protection Laws, and respecting their potential mandatory prevalence, this DPA shall be governed by and construed in accordance with the laws of the country or territory stipulated for this purpose in the Agreement and each of the Parties agrees to submit to the choice of jurisdiction as stipulated in the Agreement in respect of any claim or matter arising under or related to this DPA.

Dispute resolution. In order to resolve amicably any dispute that may arise with respect to the interpretation, the performance and/or the termination of this DPA, the Parties agree to negotiate after the receipt of a notice by one of the Parties, with the intent to solve any dispute in an amicable way. Failing for the parties to reach an amicable settlement by signing a settlement agreement within thirty (30) days following the notification by a party of the existence of the dispute and making an express reference to this provision, the Parties shall submit their dispute to the relevant court that will have jurisdiction to settle the dispute.

Exhibit A

Subject Matter of Processing

The subject matter of the processing is the Personal Data submitted to the Services by Customer pursuant to the Agreement.

Duration of Processing

The processing will continue until the expiration or termination of the Terms.

Nature and Purpose of Processing

Processing by Birdie to provide the Services to Customer pursuant to the Agreement.

The frequency of processing

On a continuous basis.

Types of Personal Data

Personal Data provided to Birdie by Customer or its Authorized Users, including:

  • Name, email address, and other account data;

  • Video, audio, and transcript data containing Personal Data;

  • Transaction logs for transactions conducted by users using the Service;

  • Information about the hardware used to access the Service;

  • Information and analytics about use of the Service;

  • Employee authentication information from the Customer helpdesk, such as user ID;

  • Other Personal Data uploaded or submitted by Customer or Authorized Users to the Services.

Exhibit B

Security Measures

Measures pseudonymizing and/or encrypting personal data

Birdie maintains Customer Content encrypted in transit with TLS and at rest with AES 256-bit encryption.

Measures for ensuring ongoing confidentiality, integrity, availability and resilience of processing systems and services

The infrastructure for the Application Services spans multiple fault-independent availability zones in geographic regions physically separated from one another; a variety of tools and processes are in place to maintain high availability and resiliency.

Measures ensuring the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident

Backups of the Customer Content are performed on a regular schedule and recovery testing is periodically conducted. Customer Content is encrypted in transit with TLS and at rest with AES 256 bit encryption.

Processes for regularly testing,assessing and evaluating the effectiveness of technical and organizational measures in order to ensure the security of the processing

Birdie maintains an enterprise-wide security program that includes administrative, organizational, technical, and physical safeguards designed to protect the confidentiality, integrity, and availability of Customer Content. Birdie conducts periodic reviews of its security program through various internal auditing services.

Measures for user identification and authorisation

Birdie enforces password and multi-factor authentication requirements. Access rights are promptly removed with personnel termination. Birdie operates under the principle of least privilege which ensures that only those with a business need to access a system or data are authorized and utilizes role-based access controls (RBAC) to provision and control access.

Measures for the protection of data during transmission

Birdie maintains Customer Content encrypted in transit with TLS.

Measures for the protection of data during storage

Birdie maintains Customer Content encrypted with AES-256 bit encryption.

Measures for ensuring physical security of locations at which personal data are processed.

Birdie hosts Personal Data primarily in AWS data centers that have been certified as ISO 27001, PCI DSS Service Provider Level 1, and/or SOC 2 compliant. AWS infrastructure services include backup power, HVAC systems, and fire suppression equipment to help protect servers and ultimately your data. AWS on-site security includes a number of features, such as, security guards, fencing, securing feeds, intrusion detection technology, and other security measures. More details on AWS controls can be found at: https://aws.amazon.com/security

Measures for ensuring events logging

Birdie maintains application and infrastructure event logs. Events logs are managed centrally and contextually by the security team.

Measures for ensuring system configuration, including default configuration

Birdie maintains a change management policy with approval processes applicable to pre-production. Hardened security configuration and vulnerability fixes are used in the production environment. Pre-production and production environments are segregated. Birdie leverages tools to minimize security exposure including essential built-in security features such as minimal read-only root file system, file system integrity check, locked-down firewall, and audit logging.

Measures for internal IT and IT security governance and management

The security program at Birdie includes administrative, organizational, technical, and physical safeguards reasonably designed to protect the confidentiality, integrity, and availability of Customer Content taking into account the nature of the services provided by Birdie and data protection laws and regulations applicable to Birdie in its performance of its services. Birdie maintains information security and privacy policies considering these aspects. These policies are approved by management, regularly reviewed, and made available to all employees.

Measures for ensuring limited data retention

Customers may delete at any time their Customer Content directly through the Application Services. Additionally, Birdie deletes the Customer Content at Customer’s request in accordance with the data processing addendum in place with its customers.

Measures for ensuring accountability

Birdie employs multiple controls to ensure high visibility and enforcement of change management policies to ensure accountability, including comprehensive system logs, code reviews, infrastructure as code, and filtering requests through a centralized ticketing solution.

Measures for allowing data portability and ensuring erasure

Customers may delete at any time their Customer Content directly through the Application Services. Additionally, Birdie deletes the Customer Content at Customer’s request in accordance with the data protection addendum in place with its customers.