Data Processing Addendum
Data Processing Addendum
This Data Processing Addendum (“DPA”) forms part of and is subject to the Software as a Service Agreement by and between the parties (“SaaS Agreement”) under which Tango provides the SaaS Services (as such term is defined in the SaaS Agreement) to Subscriber. Subscriber and Tango are collectively referred to in this DPA as the “Parties” and each a “Party”. Capitalized terms not otherwise defined in this DPA have the meaning given to them in the SaaS Agreement.
- Definitions.
- “CCPA” means the California Consumer Privacy Act of 2018, as may be amended, supplemented or replaced from time to time, including the California Privacy Rights Act of 2020.
- “Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of or access to Subscriber Personal Data.
- “Data Protection Laws” means the data protection and privacy laws applicable to the respective Party in its role in the Processing of Personal Data under the SaaS Agreement, including, as applicable, European Data Protection Laws and US Data Protection Laws.
- “Data Subject” means the identified or identifiable natural person to whom Subscriber Personal Data relates.
- “Essential Information” means Subscriber Personal Data that is (i) one of the types expressly set forth in the Schedule 1 to this DPA that is necessary for the operation, access and/or use of the SaaS Services, or (ii) expressly agreed to in writing by Tango in a mutually agreed and executed Statement of Work that expressly provides that such information is to be treated as Essential Information.
- “Non-Essential Information” means any Personal Data that is not Essential Information.
- “European Data Protection Laws” means, to the extent applicable, (i) Regulation 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the Processing of Personal Data and on the free movement of such data (General Data Protection Regulation) (“GDPR”); (ii) the GDPR as it forms part of United Kingdom law pursuant to Section 3 of the European Union (Withdrawal) Act 2018 (“UK GDPR”) and the Data Protection Act 2018; (iii) the Swiss Federal Act on Data Protection of 19 June 1992 and the Swiss Ordinance to the Swiss Federal Act on Data Protection of 14 June 1993 (collectively the “Swiss Act”) and; (iv) any implementing, supplementing, or successor legislation to those laws and regulations identified in subsections (i)-(iii) of this paragraph.
- “Personal Data” means any information relating to an identified or identifiable natural person and includes similarly defined terms in Data Protection Laws, including “personal data” under GDPR and “personal information” under the CCPA.
- “Standard Contractual Clauses” means, depending on the circumstances unique to any particular Subscriber, any of the following: (i) “EU SCCs” means the standard contractual clauses for the transfer of personal data to third countries approved pursuant to Commission Decision (EU) 2021/914 of 4 June 2021, currently found at https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection/standard-contractual-clauses-scc_en and/or; (ii) “UK Addendum” means the International Data Transfer Addendum issued by the Information Commissioner’s Office under s.119(A) of the UK GDPR, currently found at Standard Data Protection Clauses to be issued by the Commissioner under S119A(1) Data Protection Act 2018 and/or; (iii) “Swiss Addendum” means the EU SCCs as modified in Schedule 3 to this DPA to address the Swiss Act including any implementing, supplementing, or successor legislation.
- “Sub-processor” means any Processor engaged by Tango to Process Subscriber Personal Data.
- “Subscriber Personal Data” means the Personal Data contained within Subscriber Data.
- “US Data Protection Laws” means, to the extent applicable, federal and state laws relating to data protection, privacy and/or the Processing of Personal Data in force from time to time in the United States, including CCPA, Virginia Consumer Data Protection Act, Colorado Privacy Act, Utah Consumer Privacy Act, and Connecticut Data Privacy Act, including any amendments and regulations.
- The terms “Controller”, “Processor” and “Processing” (including Process, Processed, and Processes) shall have the respective meanings ascribed to them in Data Protection Laws. If and to the extent that Data Protection Laws do not define such terms, then the definitions given in European Data Protection Laws will apply.
- Scope of Application.
- Except as provided by this DPA, the SaaS Agreement remains unchanged and in full force and effect. The provisions of the Standard Contractual Clauses prevail, where applicable, over this DPA to the extent of any discrepancy between the two.
- This DPA becomes effective from the effective date of the SaaS Agreement or, if separately signed, the date last signed by the Parties below (“Effective Date”) and remains in effect for as long as Tango Processes Subscriber Personal Data pursuant to the SaaS Agreement.
- Roles of Parties.
- For the purposes of European Data Protection Laws, Tango acts as a Processor on behalf of the Subscriber who acts as either: (i) a Controller; or (ii) a Processor on behalf of another Controller.
- For the purposes of US Data Protection Laws, Tango acts as a “service provider” or “processor” (as defined under US Data Protection Laws), as applicable, in its performance of its obligations pursuant to the SaaS Agreement.
- As between the Parties, Subscriber is and remains the owner of Subscriber Personal Data and the holder of all rights relating to Subscriber Personal Data.
- Processing of Subscriber Personal Data Pursuant to Subscriber’s Instructions.
- Each Party will comply with its respective obligations under Data Protection Laws. Tango shall Process Subscriber Personal Data solely on behalf of Subscriber and on Subscriber’s written instructions which are set forth in the SaaS Agreement and this DPA. Any additional requested instructions require the prior written agreement of the Parties. Tango shall promptly notify Subscriber if Tango determines that such instructions conflict with Data Protection Laws.
- Tango must notify Subscriber in writing and without delay if Tango determines that it can no longer meet its obligations under Data Protection Laws. Upon such notice, Subscriber may direct Tango to take reasonable and appropriate steps to stop and remediate unauthorized use of Subscriber Personal Data by suspending the relevant Processing operations and/or deleting all or the relevant portion of Subscriber Personal Data; or by such other means as agreed to by the Parties.
- The details of the Processing of Subscriber Personal Data under the SaaS Agreement and this DPA (e.g., subject matter, nature, duration and purpose of the Processing, categories of Personal Data and Data Subjects) are set forth in Schedule 1 to this DPA.
- Subscriber expressly agrees that Subscriber shall not provide to Tango, import into the SaaS Services, or cause Tango to Process any Non-Essential Information, unless Tango expressly agrees to treat such information as Essential Information in a mutually agreed and executed Statement of Work. If Tango does not expressly agree to Process Non-Essential Information as Essential Information pursuant to the previous sentence, Tango has no obligations or liability with respect such data. If Subscriber inadvertently provides or causes Tango to Process any Non-Essential Information that is Subscriber Personal Data, Subscriber shall, at Subscriber’s sole cost: (a) immediately notify Tango in writing; (b) take all necessary steps to assist Tango in removing Non-Essential Information from Tango’s systems.
- Subscriber Obligations.
- Subscriber is responsible for obtaining all necessary consents, permissions and rights required under Data Protection Laws for Tango to lawfully Process Subscriber Personal Data on behalf of Subscriber in order to provide the SaaS Services and Professional Services to Subscriber.
- Subscriber shall not issue Processing instructions that would cause Tango to Process Subscriber Personal Data in violation of Data Protection Laws.
- Tango shall have no obligation to assess the contents or accuracy of Subscriber Personal Data.
- Security of Processing.
- Tango takes appropriate technical and organizational measures to ensure an adequate level of protection for Subscriber Personal Data corresponding to the risk of the respective Processing. Such measures are in consideration of the state of the art, implementation costs and the type, scope, circumstances, and aims of the Processing as well as the varying likelihood and severity of risk to the rights and freedoms of Data Subjects.
- Tango’s technical and organizational measures are set forth in Schedule 2 to this DPA. Tango will maintain those (or effectively similar) measures throughout the term of the SaaS Agreement.
- Tango shall ensure that any person who is authorized by Tango to Process Subscriber Personal Data shall be under an appropriate obligation of confidentiality (whether a contractual or statutory duty).
- Sub-processors.
- Subscriber hereby authorizes Tango to appoint Sub-processors in accordance with this section.
- Subscriber hereby authorizes the use of the Sub-processors engaged by Tango as of the Effective Date and that are listed in Schedule 3, Section 2 subject to Tango meeting the obligations set out in this section.
- Tango will notify Subscriber in advance of any addition or replacement of the Subprocessors, as reported in the applicable DPA Exhibit or Sub-processor Site. Within 30 days after Tango’s notification, Subscriber may object in writing stating specific reasons and possible mitigations, if any. If Subscriber does not object within such period, the Subprocessor may process Subscriber Personal Data. Tango shall impose substantially similar but no less protective data protection obligations as set out in this DPA on any approved Subprocessor prior to the Subprocessor initiating any Processing of Subscriber Personal Data.
- If Subscriber reasonably objects to a Subprocessor and Tango cannot reasonably accommodate the objection, Tango will notify Subscriber. Subscriber may terminate the affected services, otherwise the parties shall cooperate to find a feasible solution in accordance with the dispute resolution process, as set out in the Agreement, if applicable.
- Data Subject Requests. Tango will notify Subscriber of Data Subjects requests addressed directly to Tango, where the Data Subject has provided information to identify Subscriber. If identified, Tango will direct the Data Subject to Subscriber. Subscriber shall be responsible for handling such requests with Tango providing reasonable assistance under Section 14.b.
- Third Party Requests.
- Tango will not disclose Subscriber Personal Data to any third party, unless authorized by the Subscriber or required by law. If a government or Supervisory Authority demands access to Subscriber Personal Data:
- Tango will notify Subscriber of such request to enable Subscriber to take all necessary actions to communicate directly with the relevant authority and respond to such request.
- If Tango is prohibited by law to notify Subscriber of such request, it will make best reasonable efforts to challenge such prohibition and it commits to providing the minimum amount of information permissible when responding, based on a reasonable interpretation of the order.
- Tango will provide to Subscriber general information relative to any such request received from a government or Supervisory Authority during the preceding 12-month period.
- Tango requires all of its personnel authorized to Process Subscriber Personal Data to commit themselves to the requirements of this section.
- Data Breach.
- If Tango becomes aware of a Data Breach, it will notify Subscriber without undue delay and, in any case, within 72 hours after becoming aware, so as to facilitate the Parties’ compliance with Data Protection Laws. Tango shall notify Subscriber, to the extent known, about the nature of the Data Breach, the identities, categories and number of Data Subjects affected, and the number of data sets affected.
- Tango will, without undue delay, take all necessary and reasonable measures to mitigate or contain the Data Breach. Tango will inform Subscriber as soon as reasonably possible about such measures and keep Subscriber informed as reasonably practicable.
- Tango’s notification of or response to a Data Breach will not be construed as an acknowledgement by Tango of any fault or liability with respect to the Data Breach.
- Return and deletion of Subscriber Personal Data.
- Subject to Section 10.b, within 30 days of written request by Subscriber or upon termination or expiration of the SaaS Agreement, Tango will delete (such that it cannot be recovered or reconstructed) all Subscriber Personal Data within its possession or control.
- Tango may retain Subscriber Personal Data after termination of the SaaS Agreement only to the extent and for such period as required by Data Protection Laws. Any Subscriber Personal Data retained by Tango under this section shall be Processed in compliance with the terms of this DPA and shall only be Processed as necessary for the purposes specified in the Data Protection Laws requiring its retention.
- Cross Border Data Transfers Mechanism. If any Subscriber Personal Data transfer between Subscriber and Tango requires execution of Standard Contractual Clauses in order to comply with European Data Protection Laws (where Subscriber is the Data Exporter), the terms and conditions of Schedule 3 will apply.
- Audit. Subject to the appropriate confidentiality and Section 14.b., Tango shall allow for, and contribute to, audits conducted by Client or another auditor mandated by Client, who shall be not a direct competitor of Tango, including inspections to the extent required by the applicable Data Protection Laws, in accordance with the following procedures:
- Tango will provide Subscriber or its mandated auditor with the most recent certifications and/or summary audit report(s), which Tango has procured to regularly test, assess and evaluate the effectiveness of the TOMs.
- Tango will reasonably cooperate with Subscriber by providing available additional information concerning the TOMs, to help Subscriber better understand such TOMs.
- If further information is needed by Subscriber to comply with its own or other Controllers audit obligations or a competent Supervisory Authority’s request, Subscriber will inform Tango in writing to enable Tango to provide such information or to grant access to it.
- To the extent it is not possible to otherwise satisfy an audit right mandated by applicable law or expressly agreed by the Parties, only legally mandated entities (such as a governmental regulatory agency having oversight of Subscriber’s operations), Subscriber or its mandated auditor may conduct an onsite visit of the Tango facilities used to provide the SaaS Services, during normal business hours and only in a manner that causes minimal disruption to Tango’s business, subject to coordinating the timing of such visit in order to reduce any risk to Tango’s other customers.
- Cooperation Obligations.
- If Subscriber is required to provide information to a supervisory authority or to otherwise cooperate with a public authority, relating to Processing of Subscriber Personal Data, Tango will support Subscriber by providing such information reasonably available to it or otherwise reasonably cooperating with Subscriber.
- Subscriber will make a written request for any assistance under this DPA. The Parties shall reasonably cooperate on a mutually feasible solution in accordance with this DPA and the SaaS Agreement.
- Relationship to SaaS Agreement.
- This DPA shall replace and supersede any existing data processing addendum, attachment, exhibit or standard contractual clauses that Tango and Subscriber may have previously entered into in connection with the SaaS Services and Professional Services provided by Tango to Subscriber. This DPA is subject to the governing law and jurisdiction provisions in the SaaS Agreement unless and to the extent required otherwise by Data Protection Laws.
- Each Party and each of its Affiliates’ liability, taken in the aggregate, arising out of or related to this DPA (including the Standard Contractual Clauses where applicable) are subject to the limitations and exclusions of liability set out in the SaaS Agreement.
Schedule 1: Details of Processing
For purposes of the Standard Contractual Clauses in Schedule 3, this Schedule 1 serves as Annex I, Part B.
| Categories of Subscriber Personal Data | “Essential Information” means the following categories of Subscriber Personal Data that is necessary for the operation, access and/or use of the SaaS Services: Usernames to access the SaaS Services Passwords to access the SaaS Services Business e-mail addresses Business phone numbers Business or property addresses Authorized User’s first and last name Authorized User’s employee ID number Additional categories of data that Tango expressly agrees to Process as Essential information in a mutually agreed and executed Statement of Work that expressly provides that such information is to be treated as Essential Information under this DPA. No Sensitive Personal Data or other “special categories of personal data” are transferred. |
|---|---|
| Categories of Data Subjects | Data Subjects include the Subscriber’s Authorized Users only. |
| Duration of Processing | Duration of the SaaS Agreement. |
| Frequency of Processing | Continuous basis for the duration of the SaaS Agreement. |
| Nature of Processing | Any operation necessary for the performance of the SaaS Agreement and any related Support, Training or Professional Services associated therewith; monitoring, supporting and maintaining Tango’s services; improving the performance or function of any product or service offered by Tango; developing new features, functions or products or service offered by Tango; and aggregating data with other data and creating derived data for any lawful purpose. Subscriber agrees that Tango may use the Data to assess claims related to the above purposes. Subscriber agrees that Tango may share the Data with third parties under contract with Tango only for the above purposes. |
| Purposes of Processing | The performance of the SaaS Agreement and any related Support, Training or Professional Services associated therewith; monitoring, supporting and maintaining Tango’s services; improving the performance or function of any product or service offered by Tango; developing new features, functions or products or service offered by Tango; and aggregating data with other data and creating derived data for any lawful purpose. |
| Competent Supervisory Authority | The competent supervisory authority shall be the Irish Data Protection Commission. |
Schedule 2: Technical and Organizational Measures (“TOMs”)
1. Overview
Tango implements and maintains appropriate technical and organizational measures designed to protect the confidentiality, integrity, and availability of Subscriber Personal Data. These measures are designed to ensure a level of security appropriate to the nature, scope, context, and size of Tango’s business operations. These measures apply globally across Tango products and services, unless explicitly stated otherwise.
2. Governance & Information Security Program
Tango maintains a formal, documented Information Security Program approved by executive management. The security program is based on industry-standard frameworks including the NIST Cybersecurity Framework (CSF) and ISO27001:2022. Tango’s controls are audited annually by qualified and impartial independent external auditors.
Responsibility for the security program is assigned by Tango to the Chief Information Security Officer or another designated security leadership role with authority over policy enforcement and risk management.
Security policies are reviewed, updated (as required), and approved at least annually.
3. Access Control & Identity Management
- Access to systems and data is restricted based on job role and business need (“least privilege”).
- Unique user accounts are required. Shared accounts are prohibited except for controlled service accounts.
- Access rights are reviewed periodically and promptly revoked upon role change or termination.
3.2 Authentication
- Strong password requirements and multi-factor authentication are enforced for internal users.
- Administrative and privileged access is restricted and subject to additional technical security measures.
- All access attempts are logged and monitored, and suspicious access events are investigated.
4. Encryption & Key Management
- Data transmitted over public or untrusted networks is encrypted using industry-standard cryptographic protocols.
- Customer data stored in production systems is encrypted at rest using strong encryption (AES-256 or equivalent). Full-disk encryption is enforced on corporate endpoints.
5. Secure Software Development & Change Management
5.1 Secure Development Lifecycle
- Tango follows a documented Secure Software Development Lifecycle (SSDLC).
- Security requirements are incorporated during design and development.
- Code changes undergo peer review and security testing prior to release.
5.2 Security Testing
- Automated and manual security testing is performed, including vulnerability scanning and dependency analysis.
- Identified security issues are tracked, prioritized, and remediated according to defined SLAs.
5.3 Change Management
- Changes to production systems follow a formal change management process, including risk assessment, testing, and approval.
6. Infrastructure & Asset Security
6.1 Asset Management
- Information assets and systems are inventoried and assigned ownership.
- Cloud and endpoint assets are monitored for security posture and configuration drift.
- Assets are securely decommissioned at end of life, including data sanitization.
6.2 Endpoint Security
- Corporate endpoints are managed and monitored.
- Anti-malware protection and security monitoring are enforced.
7. Logging, Monitoring & Vulnerability Management
- Security-relevant events are logged and monitored.
- Logs are protected against unauthorized modification.
- Vulnerabilities are identified through regular scanning and remediated according to risk-based timelines.
- Security alerts are investigated and escalated as appropriate.
8. Incident Management & Breach Response
- Tango maintains a documented Information Security Incident Response Plan.
- Personnel are trained to identify and report suspected security incidents.
- Incidents are investigated, contained, remediated, and documented.
9. Business Continuity & Disaster Recovery
- Tango maintains documented Business Continuity and Disaster Recovery plans.
- Backup and recovery mechanisms are implemented for production systems.
- Plans are tested periodically and updated based on test results and operational changes.
10. Personnel Security & Training
- Background screening is performed where legally permissible prior to granting system access.
- Security awareness training is provided during onboarding and refreshed periodically.
- Employees are bound by confidentiality obligations.
11. Third-Party & Sub-processor Management
- Tango assesses the security posture of material third-party service providers.
- Security and confidentiality obligations are addressed contractually with sub-processors.
- Sub-processors are monitored based on risk and service criticality.
12. Continuous Improvement
- Tango regularly reviews and improves its security controls based on:
- Risk assessments
- Security incidents and lessons learned
- Changes in technology and threat landscape
Schedule 3 – Standard Contractual Clauses
- Data Transfer.
- For data transfers by Subscriber from the European Economic Area, the United Kingdom or Switzerland to Tango in a country that does not ensure an adequate level of protection within the meaning of Data Protection Laws, the EU SCCs and/or UK Addendum and/or Swiss Addendum, as applicable, shall govern such transfers.
- The Parties agree that entering into this DPA constitutes execution of the SCC and that their respective roles as Controller and Processor determine the applicable SCC module for each transfer, and the relevant obligations.
- Subscriber agrees that the SCC are subject to the terms of the SaaS Agreement and DPA, including the limitations of liability for any claims arising from them. In case of conflict, this provisions of the SCC shall prevail.
- If required by applicable Data Protection Laws, Subscriber shall obtain consent from the Data Subjects for the transfer of Subscriber Personal Data to non-adequate countries.
- EU Standard Contractual Clauses
- The Standard Contractual Clauses, as approved by EU Commission (EU SCC) apply to the transfer of Client Personal Data subject to the Regulation (EU) 2016/679 (GDPR).
- The EU SCC are completed as set out below.
| Section Reference | Concept | Selection by the Parties |
|---|---|---|
| Section I, Clause 5 | Docking Clause | The optional Docking Clause shall apply. |
| Section II, Clause 7 | Approval of Subprocessors | Option 2: General Written Authorization shall apply in accordance with the notification period set out in Section 7 of the DPA. |
| Section II, Clause 9 | Redress | The optional language shall not apply. |
| Section III, Clause 14 | Governing Law | The Parties agree that this shall be the law of Switzerland. |
| Section III, Clause 15 | Choice of forum and jurisdiction | The courts of the EU Member State where the competent supervisory authority is located, according to Clause 14. |
| Annex A. | List of Parties | Subscriber is the data exporter. Tango is the data importer. |
| Annex B. | Description of the transfer. | This Annex shall be deemed to be completed with the information from Schedule 1 of the DPA. |
| Annex C. | Administrative, Physical and Technical Measures to Ensure Data Security | This Annex shall be deemed to be completed with the information from Schedule 2 of the DPA. |
| Annex D | List of Data Subprocessors | See below. |
Annex D – Scope: All Tango Products
| Sub-processor | Nature and Purpose of Processing | Location(s) of Processing | Security Measures |
|---|---|---|---|
| Freshworks | Customer Support | USA | Freshworks Trust Center |
| Microsoft SharePoint | Implementation collaboration with customers | USA | Microsoft Trust Center |
| Atlassian | Implementation collaboration with customers | USA | Atlassian Trust Center |
Scope: Tango Core and Edge (list all modules)
| Sub-processor | Nature and Purpose of Processing | Location(s) of Processing | Security Measures |
|---|---|---|---|
| AWS | Cloud hosting provider | Available locations include USA, Australia | AWS Compliance Programs |
| Microsoft Azure* | Cloud hosting provider | USA | Microsoft Trust Center |
*Microsoft Azure hosts a limited number of customer environments. Most Tango customers leverage AWS hosting.
Scope: Reserve
| Sub-processor | Nature and Purpose of Processing | Location(s) of Processing | Security Measures |
|---|---|---|---|
| AWS | Cloud hosting provider | Available locations include USA, Canada, EU, and Australia | AWS Compliance Programs |
Scope: E&S
| Sub-processor | Nature and Purpose of Processing | Location(s) of Processing | Security Measures |
|---|---|---|---|
| AWS | Cloud hosting provider | Available locations include USA, Australia | AWS Compliance Programs |
| Files.com | Customer Data Ingestion (SFTP) | USA | Files.com Compliance Overview |
Scope: Occupancy
| Sub-processor | Nature and Purpose of Processing | Location(s) of Processing | Security Measures |
|---|---|---|---|
| AWS | Cloud hosting provider | USA | AWS Compliance Programs |
| Google Cloud | Cloud hosting provider | EU | Google Cloud Trust Center |
- UK Addendum
The International Data Transfer Addendum to the EU Commission Standard Contractual Clauses as approved by the UK Information Commissioner’s Office (the “UK Addendum”), apply to the transfer of Subscriber Personal Data subject to the UK GDPR. The UK Addendum shall be deemed executed by the parties as an addendum to EU SCC (including its Annexes) completed as set out above in Section 2.b. of this Schedule 3 to the DPA.
The Mandatory Clauses of the UK Addendum apply in full. The information required for Table 1 to 4
of the UK Addendum is set out in the Annexes to the EU SCC, completed as above.
- Swiss Addendum
For transfers of Subscriber Personal Data that are subject to the Swiss Act, the EU SCCs form part of this Swiss Addendum, but with the following differences to the extent required by the Swiss Data Protection Laws.
- References to the GDPR in the EU SCCs shall be references to Swiss Data Protection Laws to the extent the data transfers are subject exclusively to Swiss Data Protection Laws and not to the GDPR.
- References to the “European Union”, “Union”, “EU” and “EU Member State” are all replaced with “Switzerland”.
- The “competent supervisory authority” is the Federal Data Protection and Information Commissioner insofar as the transfers are governed by Swiss Data Protection Laws.
- References to “personal data” in the EU SCCs also refer to data about identifiable legal entities until the entry into force of revisions of Swiss Data Protection Laws that eliminate this broader scope.
- Clause 18 of the EU SCCs is replaced to state: “Any dispute arising from these Clauses relating exclusively to Swiss Data Protection Laws will be resolved by the courts in Switzerland. A Data Subject may also bring legal proceedings against the data exporter and/or data importer before the courts of Switzerland in which he/she has his/her habitual residence.”