Data Processing Addendum
This Data Processing Addendum ("Addendum") forms part of the agreement between Ahum, Inc., a Delaware corporation having its principal place of business at 2400 Broadway, Suite 200, Redwood City, CA 94063, USA ("Ahum"), and the customer entity identified in that agreement ("Customer") for the provision of the Services (the "Agreement"). It reflects the parties' agreement with respect to the Processing of Customer Personal Data.
1. Definitions
1.1 "CCPA" means the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act, and its implementing regulations.
1.2 "Customer Personal Data" means Personal Data contained within data supplied or disclosed to, or Processed through, the Services by or on behalf of Customer.
1.3 "Data Processing Schedule" means the schedule set out in the Annex to this Addendum, which sets out the subject matter, nature and purpose of the Processing, its duration, the types of Personal Data and categories of Data Subjects concerned, and the current Sub-processors.
1.4 "Data Protection Laws" means all laws applicable to the Processing of Customer Personal Data under this Addendum, including the GDPR, the UK GDPR and Data Protection Act 2018, and the CCPA, in each case as amended or replaced from time to time.
1.5 "GDPR" means Regulation (EU) 2016/679 of the European Parliament and of the Council.
1.6 "Services" means the Ahum hosted software product and related services provided under the Agreement.
1.7 "Standard Contractual Clauses" means the standard contractual clauses for the transfer of personal data to third countries adopted by the European Commission, and any equivalent mechanism adopted under the laws of the United Kingdom or Switzerland.
1.8 "Sub-processor" means any third party engaged by Ahum to Process Customer Personal Data in connection with the Services.
1.9 The terms "Controller", "Processor", "Data Subject", "Personal Data", "Personal Data Breach", "Process", "Processing" and "Supervisory Authority" have the meanings given to them in the GDPR.
2. Relationship between the Parties and Nature of the Processing
2.1 With respect to Customer Personal Data, Customer is the Controller and Ahum is the Processor. Where Customer is itself acting as a processor on behalf of a third party controller, Ahum acts as a sub-processor and Customer warrants that it has the authority to enter into this Addendum on that controller's behalf.
2.2 The subject matter, nature and purpose of the Processing, its duration, the types of Personal Data and the categories of Data Subjects are set out in the Data Processing Schedule.
2.3 This Addendum does not apply to Personal Data for which Ahum is the Controller, including information relating to the registration and administration of user accounts, which is described in the Ahum Privacy Notice.
3. Security
3.1 Ahum shall implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure or access, having regard to the state of the art, the costs of implementation, and the nature, scope, context and purposes of the Processing.
3.2 Such measures include the encryption of Customer Personal Data in transit and at rest; logical separation of each customer's data; access controls restricting access to authorized personnel on a least-privilege basis and requiring multi-factor authentication; logging of administrative access; and regular testing and assessment of the effectiveness of those measures.
3.3 Ahum maintains an information security program and undergoes an annual independent SOC 2 Type 2 examination. Ahum may update its security measures from time to time provided that such updates do not materially reduce the overall level of protection afforded to Customer Personal Data.
4. Instructions
4.1 Ahum shall Process Customer Personal Data only in accordance with Customer's documented instructions, which are given by the Agreement, this Addendum, and Customer's configuration and use of the Services, except where required to do otherwise by applicable law. Where such a legal requirement applies, Ahum shall inform Customer before Processing unless that law prohibits it.
4.2 Ahum shall not sell or share Customer Personal Data, shall not retain, use or disclose it for any purpose other than performing the Services, and shall not use it for marketing purposes or to train machine learning models for the benefit of any party other than Customer.
4.3 Ahum shall inform Customer if, in its opinion, an instruction infringes Data Protection Laws.
5. Personnel
5.1 Ahum shall ensure that access to Customer Personal Data is limited to personnel who require it to perform the Services, and that such personnel are subject to a duty of confidentiality and have received appropriate data protection training.
6. Assistance
6.1 Taking into account the nature of the Processing, Ahum shall provide reasonable assistance to Customer, at Customer's cost, in fulfilling Customer's obligations to respond to requests from Data Subjects exercising their rights under Data Protection Laws.
6.2 Where Ahum receives a request directly from a Data Subject relating to Customer Personal Data, Ahum shall not respond to it other than to refer the Data Subject to Customer, unless legally required to do otherwise.
6.3 Ahum shall provide reasonable assistance to Customer with data protection impact assessments and prior consultations with Supervisory Authorities, insofar as these relate to Ahum's Processing and taking into account the information available to Ahum.
7. Personal Data Breach Notification
7.1 Ahum shall notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, and shall provide such information as is reasonably available to enable Customer to meet its own notification obligations.
7.2 Ahum shall take reasonable steps to contain, investigate and remediate the Personal Data Breach, and shall cooperate with Customer in doing so. Ahum's notification of a Personal Data Breach is not an acknowledgement of fault or liability.
8. Deletion and Return of Customer Personal Data
8.1 On termination or expiry of the Agreement, Ahum shall, at Customer's election, return Customer Personal Data in a structured, commonly used and machine-readable format or delete it, in either case within thirty (30) days of a written request made within thirty (30) days of termination.
8.2 Section 8.1 does not apply to copies retained in routine backups, which are overwritten in accordance with Ahum's backup cycle, or to Personal Data that Ahum is required by applicable law to retain, including records held in immutable storage for a fixed regulatory retention period. Any such data remains subject to this Addendum for as long as it is retained.
9. Audits
9.1 Ahum shall make available to Customer the information reasonably necessary to demonstrate compliance with this Addendum. Ahum's current SOC 2 Type 2 report shall ordinarily satisfy this obligation and is available to Customer on request under an appropriate confidentiality undertaking.
9.2 Where Data Protection Laws require an audit beyond the information described in Section 9.1, Customer may, no more than once in any twelve (12) month period and on at least thirty (30) days' prior written notice, conduct or mandate an independent auditor to conduct such an audit, subject to reasonable confidentiality obligations, during business hours, and in a manner that does not disrupt Ahum's operations or the security or confidentiality of any other customer's data. Customer shall bear the cost of any such audit.
10. Sub-processors
10.1 Customer provides general authorization for Ahum to engage Sub-processors. The Sub-processors engaged as at the date of this Addendum are listed in Section F of the Annex.
10.2 Ahum shall impose on each Sub-processor data protection obligations no less protective than those set out in this Addendum, and remains liable to Customer for the performance of each Sub-processor's obligations.
10.3 Ahum shall give Customer no less than thirty (30) days' prior notice of the addition or replacement of a Sub-processor. Customer may object on reasonable data-protection grounds within thirty (30) days of that notice, in which case the parties shall work in good faith to resolve the objection; if it cannot reasonably be resolved, Customer may terminate the affected Services.
11. International Data Transfers
11.1 Ahum Processes Customer Personal Data in the United States. Ahum shall not transfer Customer Personal Data to a jurisdiction outside the United States except in accordance with this Section.
11.2 Where Customer Personal Data originating in the European Economic Area, the United Kingdom or Switzerland is transferred to a country not the subject of an adequacy decision, Ahum shall enter into the Standard Contractual Clauses or shall implement an equivalent transfer mechanism recognized under Data Protection Laws.
12. Data Access by Public Authorities
12.1 If Ahum receives a legally binding request from a public authority for disclosure of Customer Personal Data, Ahum shall notify Customer without undue delay unless prohibited from doing so by law, shall seek to challenge or narrow the request where there is a reasonable basis to do so, and shall disclose only the minimum amount of data required.
13. California Consumer Privacy Act
13.1 Where the CCPA applies, Ahum acts as a Service Provider with respect to Customer Personal Data. Ahum shall not sell or share such data, shall not retain, use or disclose it for any purpose other than performing the Services specified in the Agreement, and shall not retain, use or disclose it outside the direct business relationship between the parties or combine it with personal information obtained from other sources, except as permitted by the CCPA.
13.2 Ahum certifies that it understands and shall comply with the restrictions in Section 13.1.
14. General
14.1 In the event of any conflict between this Addendum and the Agreement in relation to the Processing of Customer Personal Data, this Addendum prevails.
14.2 This Addendum takes effect on the effective date of the Agreement and continues until Ahum ceases to Process Customer Personal Data.
14.3 Except as expressly modified here, the Agreement remains in full force and effect. Each party's liability under this Addendum is subject to the limitations and exclusions of liability set out in the Agreement.
14.4 This Addendum is governed by the law and subject to the jurisdiction stated in the Agreement.
Annex — Data Processing Schedule
This Annex forms part of the Addendum.
A. Subject matter and duration
The provision of the Services to Customer under the Agreement. Processing continues for the duration of the Agreement and thereafter only as permitted by Section 8.
B. Nature and purpose of the Processing
Ahum ingests IT service management and device management records from Customer's own systems at Customer's direction, and Processes them in order to normalize and deduplicate records across sources; classify, categorize and enrich service tickets; correlate tickets with the devices and users to which they relate; generate automated investigations and recommendations; and make the resulting records searchable within the Console.
C. Categories of Data Subjects
Personnel of Customer, including employees, contractors and other individuals whom Customer authorizes to use its IT systems, who: raise, are assigned, are named in, or comment on a service ticket; or are recorded in Customer's device management systems as a user of a managed device.
D. Types of Personal Data
Service ticket records — ticket subject and description, comments, attachments, requester, assignee and assignment group, category and status, configuration item references, tags and custom fields. The free-text fields of a service ticket are determined by Customer's own users and may contain any category of Personal Data those users choose to enter, including, in principle, special categories of Personal Data.
Device records — device display name and hostname, which commonly incorporate an individual's name, together with hardware and platform identifiers such as serial numbers.
Directory user records — user principal name, email address, username, directory identifier, the nature of the individual's relationship to a device, and the date and time of that individual's most recent logon to it.
Investigation output — automated analyses generated from the records above, which may reproduce Personal Data contained in them.
E. Retention and deletion
Customer Personal Data is retained for the duration of the Agreement. On termination it is deleted in accordance with Section 8, including by deletion of the encryption keys applicable to Customer's data, which renders any remaining encrypted copies unrecoverable.
F. Sub-processors
- Amazon Web Services, Inc. — cloud infrastructure hosting and machine learning inference. United States.
- Anthropic, PBC — machine learning inference supporting automated classification, enrichment and investigation. United States.
- ClickHouse, Inc. — analytics data store. United States.
- Descope Inc. — authentication, single sign-on and user provisioning. United States.
- LangChain, Inc. (LangSmith) — capture of model interaction traces for diagnostic purposes. United States.
- OpenAI, L.L.C. — machine learning inference supporting automated classification and reporting. United States.
- Pinecone Systems, Inc. — vector search index supporting ticket similarity search. United States.
- Resend, Inc. — transactional email delivery. United States.
- Temporal Technologies Inc. — durable workflow orchestration for automated investigations. United States.
Inference is also performed within Amazon Web Services, which is listed above. Ahum's agreements with each model provider prohibit the use of data submitted through their interfaces to train their models.
Ahum also engages providers of infrastructure services, such as domain name resolution, which do not Process Customer Personal Data and are accordingly not listed as Sub-processors.