Legal
Data Processing Agreement

- Introduction & Scope
This Runpod Data Processing Agreement (“DPA”) forms part of the Runpod Master Services Agreement (“Agreement”) between Runpod Inc. (collectively “Runpod” or the “Processor”) and (“Customer” or “Controller”). Customer and Runpod are separately referred to as “Party” and collectively as “Parties”.
In the course of providing the Services (as defined herein), the Processor may obtain access to Personal Data on behalf of the Controller. The Parties acknowledge that it is necessary to enter into this DPA to establish the respective rights and obligations of the Controller and the Processor with respect to the collection, Processing, and use of Personal Data, and to ensure that such Personal Data is afforded a level of protection no less than that maintained by the Controller. This DPA sets forth the subject matter and duration of the Processing, the nature and purpose of the Processing, the types of Personal Data to be Processed, the categories of Data Subjects concerned, and the obligations and rights of the Controller and the Processor in relation thereto.
To execute this DPA, Customer must complete the signature block and required information and submit the signed DPA to Runpod via email to [email protected]. This DPA shall become legally binding only upon completion of all such steps. Any modifications, alterations, or amendments to the content of this DPA by Customer shall prevent the formation of a binding agreement between the Parties, and Runpod shall not be liable for any amounts claimed under a DPA that has not strictly met all requirements for formation or that has been modified by Customer.
- Definitions
Capitalized terms not defined in this DPA shall have the meaning given to them in the Agreement and in the applicable laws.
“Customer Personal Data” means any Personal Data Processed by Processor or its Sub-Processor on behalf of Customer to perform the Services under the Agreement (including, for the avoidance of doubt, any such Personal Data comprised within Customer Data).
“Data Protection Laws” means the privacy, data protection and data security laws and regulations of any jurisdiction applicable to the Processing of Customer Personal Data under the Agreement, including, without limitation, GDPR and FADP.
“GDPR” means, as and where applicable to Processing concerned: (i) the General Data Protection Regulation (EU) 2016/679 (“EU GDPR”); and/or (ii) the UK General Data Protection Regulation (“UK GDPR”); each as amended.
“Data Subject” means an identified or identifiable natural person to whom Customer Personal Data relates.
“Data Subject Request” means the exercise by a Data Subject of its rights in accordance with Data Protection Laws in respect of Customer Personal Data and the Processing thereof.
“EEA” means the European Economic Area.
“Effective Date” means the effective date of the Agreement.
“FADP” means, as and where applicable to Processing concerned, the Federal Act on Data Protection of 19 June 1992 in its revised version of 25 September 2020, as amended.
“FDPIC” means the Swiss Federal Data Protection and Information Commissioner.
“ICO” means the United Kingdom’s Information Commissioner’s Office (or its successor).
“Performance Data” means any log files, metadata, telemetry data, and other technical performance data automatically generated by the Service relating to the use, performance, efficacy, reliability, and/or accuracy of the Runpod Services (certain of which may constitute Personal Data).
“Personal Data” or “personal data” means any information about, or relating to an identified or identifiable natural person as defined by Data Protection Laws.
"Special Categories of Personal Data" means personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or a natural person's sex life or sexual orientation, as defined in Article 9(1) of the GDPR and any equivalent provision under applicable Data Protection Laws.
“Personal Data Breach” means a breach of security leading to accidental or unlawful destruction, loss, or alteration, unauthorized disclosure of, or access to, Personal Data processed for Customer by Processor. For clarity, Personal Data Breach does not include unsuccessful attempts or activities that do not compromise the security of Customer Personal Data (such as unsuccessful log-in attempts, pings, port scans, denial of service attacks, or other network attacks on firewalls or networked systems).
“Personnel” means a person’s employees, agents, consultants or contractors.
“Privacy Statement” means the privacy statement adhered to by Runpod in provision of all Runpod Offerings, as published and updated from time to time on Runpod’s Website Privacy policy.
“Process” (and its inflections) shall have the meaning given to that term under applicable Data Protection Laws.
“Restricted Transfer” means any transfer of Personal Data to a third country not benefiting from an adequacy decision under applicable Data Protection Laws (whether from Customer to Runpod, from Runpod to a Sub-Processor, or between establishments of Runpod or a Sub-Processor) that would be prohibited by Data Protection Laws absent appropriate authorization mechanisms.
“Services” means Runpod services and products ordered or subscribed to by the Customer in the Agreement.
“Standard Contractual Clauses” means the standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council approved by implementing decision (EU) 2021/914 of the European Commission of 4.6.2021, as may be amended, superseded, or replaced.
“Sub-Processor” means any person or entity appointed by or on behalf of Runpod to process Personal Data on behalf of Runpod in connection with the Services and shall include any Sub-Processor rightfully appointed by a Sub-Processor (a Sub-Sub-Processor) to process Personal Data on behalf of Runpod in connection with the Services, but shall not include any individual employee of Runpod or a Sub-Processor.
“Supervisory Authority” means, in the context of the EU GDPR, the authority as defined in Article 4(21) thereof, in the context of the UK GDPR, the ICO, and in the context of the FADP, the FDPIC.
“UK Addendum” means the template addendum B1.0 issued by the ICO under s119A(1) of the Data Protection Act 2018, in force from 21 March 2022, as may be amended in accordance with its terms.
- Details of the Processing, Data Categories, and Data Subjects
Runpod collects, uses, and discloses Customer Personal Data solely for the purposes of providing the Services and for such other ancillary purposes consented to by the Customer or as required by law. Processing operations are limited to those required to perform the Services in accordance with the Agreement. Runpod shall not determine the purposes for which or the manner in which Customer Personal Data is processed, and neither Runpod nor its Sub-Processors shall process Customer Personal Data for their own purposes. The following categories of Personal Data may be processed: (i) personal data (e.g., last name, first name, and address); (ii) communication data (e.g., email); (iii) IT usage data (e.g., user ID, and roles); and/or (iv) any other category named in Runpod's Privacy Statement. Customer Personal Data may relate to the following categories of Data Subjects: (a) the Customer's clients/service recipients; (b) the Customer's employees; and/or (c) the Customer's suppliers/service providers.
Where Customer Personal Data includes Special Categories of Personal Data, Customer warrants that: (i) it has identified and documented a valid legal basis under Article 9(2) of the GDPR (or equivalent provision under applicable Data Protection Laws) for such processing prior to transmitting such data to Runpod; (ii) it will promptly provide evidence of such legal basis to Runpod upon request; and (iii) it will notify Runpod in writing before adding any new Special Categories of Personal Data to the scope of processing under this DPA.
- Place of Data Processing
Runpod uses third-party data hosting providers (as identified in Attachment 2) to host the Services on servers located throughout the world, including in the United States. Where a region is specified by Customer during service instantiation, Runpod will use reasonable efforts to allocate a server in a geographically proximate location. Where cross-border transfer cannot be avoided, legally required authorization mechanisms shall be applied.
- Instructions
Runpod shall process Personal Data for the purposes of: (i) processing as required by Customer in its use of the Services; (ii) processing in accordance with the Agreement, this DPA and any other agreements between the Parties, (iii) processing to comply with other reasonable instructions provided by Customer where such instructions are consistent with the terms of the Agreement, applicable laws and DPA.
Runpod will inform Customer if, in Runpod’s opinion, the Customer’s instructions or requests are contrary to Data Protection Laws, with reasons thereof in writing via email.
Where Customer's instructions require the processing of Special Categories of Personal Data, Customer confirms that such processing is permitted under applicable Data Protection Laws and that the relevant conditions under Article 9(2) of the GDPR (or equivalent provision under applicable Data Protection Laws) are satisfied. Runpod shall process such data solely in accordance with Customer's documented instructions and shall not process it for any other purpose. If Runpod becomes aware that Customer Personal Data being processed includes Special Categories of Personal Data not previously identified by Customer, Runpod shall notify Customer promptly in writing.
- Confidentiality
Runpod shall take commercially reasonable steps to ascertain the reliability of any Processor Personnel who Process Customer Personal Data, and shall enter into written confidentiality agreements with all Processor Personnel who Process Customer Personal Data that are not subject to professional or statutory obligations of confidentiality.
- Technical & Organizational Measures
Runpod shall implement reasonably necessary technical and organizational measures (“TOMs”) designed to protect Customer Personal Data against accidental or unlawful destruction, including, as appropriate: (i) anonymization, pseudonymization, and encryption of Personal Data; (ii) security controls designed to ensure the availability and protect the confidentiality of Personal Data; and (iii) regular testing, assessing, and evaluating the effectiveness of such measures for the duration of the Agreement. The TOMs implemented by Runpod are specified in Attachment 1. Runpod reserves the right to modify the TOMs at any time, provided that any modifications shall not materially decrease the security of Customer Personal Data.
Runpod engages approved Sub-Processors to provide or support parts of the Services, and the TOMs depend partially on such Sub-Processors as described in Attachment 1; provided that Runpod remains responsible for its compliance with the TOMs regardless of its reliance on Sub-Processors.
- Sub-Processors
Customer acknowledges and agrees that Runpod may engage Sub-Processors in the provision of Services, subject to this DPA, and that (i) a Runpod affiliate may be retained as a Sub-Processor; and (ii) Runpod or a Runpod affiliate may engage third-party Sub-Processors.
Where Runpod engages a Sub-Processor in the provision of Services, a data processing agreement will be entered into with the Sub-Processor. A list of Runpod’s Sub-Processors is available in Attachment 2.
Customer further acknowledges that Runpod may, for commercial or security reasons, maintain certain Sub-Processors as confidential (“Confidential Sub-Processors”). Disclosure of any information related to Confidential Sub-Processors shall be subject to the execution of a non-disclosure agreement proposed by Runpod, and such disclosure will only occur once that agreement has been fully executed by the Parties.
Upon authorizing any new Sub-Processor to access Personal Data, Runpod will update the list of Runpod's Sub-Processors. Where a new Confidential Sub-Processor is appointed, Runpod’s notification to Customer will not identify the Sub-Processor but will state the type of services or operations it supports and the geographic location of such processing. If Customer wishes to receive additional information regarding such Confidential Sub-Processor, Customer must first execute a non-disclosure agreement proposed by Runpod, after which Runpod may disclose further details.
Within ten (10) business days of an update to the list of Sub-Processors, Customer shall inform Runpod, in writing, of objections to any new Sub-Processors, if any. If Customer objections are not unreasonable, Runpod will use reasonable efforts to change the Services provided to Customer or recommend a commercially reasonable change to Customer’s Services to avoid processing of Personal Data by the objected-to new Sub-Processor without unreasonably burdening the Customer.
If Customer objects to a new Sub-Processor, Customer may terminate any subscription for the affected Runpod Services without penalty by providing written notice of termination before the end of the notice period, unless the new Sub-Processor is necessary for Runpod to provide the Services, in which case the standard termination provisions of this DPA shall apply.
If use of a Sub-Processor involves a Restricted Transfer, Runpod shall ensure that the authorizations required under applicable Data Protection Laws are at all relevant times incorporated into an agreement between Runpod and the Sub-Processor and between the Sub-Processor and any Sub-Sub-Processor.
- Data Subject Requests
Runpod shall reasonably support the Customer in the case of a Data Subject Request, insofar as Customer cannot fulfill such a request on its own, to the extent legally permitted and technically possible. Customer shall pay Runpod for the costs for such support, to the extent legally permitted.
If a Data Subject Request is received by Runpod that relates to Personal Data transferred by the Customer, Runpod will refer the request to the Customer. Runpod will not respond to such a request but shall instead support Customer as provided in this Section.
- Personal Data Breach Notification
Runpod shall inform Customer without undue delay after becoming aware of a Personal Data Breach and shall, at Customer’s request, provide reasonable assistance in obtaining information within Runpod’s control to enable Customer to meet its obligations under Data Protection Laws to report the Personal Data Breach. Runpod's notification of or response to a Personal Data Breach shall not be construed as an acknowledgement of any fault or liability on the part of Runpod with respect to such Personal Data Breach.
At the request of Customer, but at Customer’s sole cost, Runpod shall assist Customer in notifying the relevant Supervisory Authority and/or the Data Subjects implicated in the Personal Data Breach.
Customer is solely responsible for complying with notification requirements under Data Protection Laws and fulfilling any third-party notification obligations related to any Personal Data Breaches.
If Customer determines that a Personal Data Breach must be notified to any Supervisory Authority, any Data Subject(s), the public, or any other party under Data Protection Laws, and to the extent such notice directly or indirectly refers to or identifies Runpod, Customer agrees, where permitted by applicable Data Protection Laws, to:
- notify Processor in advance; and
- consult with Processor in good faith and consider any clarifications or corrections that Processor may reasonably recommend or request in respect of such notification, provided that any such clarifications or corrections: (i) relate to Processor’s involvement in or relevance to the Personal Data Breach; and (ii) are consistent with Data Protection Laws.
- Data Protection Impact Assessment (DPIA)
Upon Customer's request, Runpod shall provide reasonable assistance in conducting a DPIA in relation to Runpod’s Processing of Customer Personal Data, taking into account the nature of the Processing and the information available to Runpod and its Sub-Processors. Customer shall bear all costs associated with such assistance, to the extent legally permitted.
- Deletion or Returning Personal Data
Upon Customer's request, Runpod shall irretrievably delete or return all Personal Data in accordance with the Agreement, unless retention is required by applicable law.
- Information & Audit Rights
Upon Customer’s written request, and no more than once per calendar year, Runpod shall make available information reasonably necessary to demonstrate Runpod's compliance with this DPA and applicable Data Protection Laws. Where Customer (acting reasonably) provides documentary evidence that such information is insufficient to demonstrate compliance, Runpod shall permit and contribute to audits, including on-premise inspections, conducted by Customer or a qualified third-party auditor appointed by Customer, in relation to the Processing of Customer Personal Data.
Prior to any audit, Customer shall submit a detailed audit plan specifying the proposed scope, duration, and start date, and providing for the confidential treatment of all information exchanged and any resulting reports. Runpod shall review the proposed plan and notify Customer of any concerns, including any request that could compromise Runpod's security, privacy, or employment policies. The Parties shall cooperate in good faith to agree on a final audit plan, including scope, timing, and duration. All costs associated with any audit shall be borne solely by Customer.
- Restricted Transfers
Any Restricted Transfer shall be subject to the Standard Contractual Clauses and/or the UK Addendum, as applicable.
In respect of any Restricted Transfer between Customer and Runpod, Customer shall be deemed the "Data Exporter" and Runpod the "Data Importer" (each as defined therein), and the Parties hereby enter into, and are deemed to have signed, the Standard Contractual Clauses in accordance with Attachment 3 and/or UK Addendum in accordance with Attachment 4. In addition, where a Restricted Transfer between Customer and Runpod is subject to the FADP, Attachment 5 of this DPA shall also apply. The Standard Contractual Clauses and/or UK Addendum entered into between Customer and Runpod shall take effect upon execution of the Agreement.
- Liability
Each Party's liability under this DPA shall be subject to the limitations, caps, and exclusions of liability set forth in the Agreement, and shall in no circumstances exceed such limitations.
- Term & Termination
This DPA shall become effective upon execution by both Parties and shall remain in force for the duration of the Agreement or for so long as Runpod Processes Personal Data on behalf of Customer, whichever is longer.
- Miscellaneous
In the event of any conflict between this DPA (or any other agreement between the Parties) and the Standard Contractual Clauses and/or UK Addendum: (a) the Standard Contractual Clauses shall prevail to the extent such conflict relates to the Processing of Personal Data under the EU GDPR; and (b) the UK Addendum shall prevail to the extent such conflict relates to the Processing of Personal Data under the UK GDPR. In the event of any conflict between this DPA and any other agreement between the Parties, this DPA shall prevail. If any provision of this DPA is or becomes invalid, the remaining provisions shall remain in full force and effect. Without prejudice to Clause 17 (Governing Law) and Clause 18 (Forum and Jurisdiction) of the Standard Contractual Clauses, and Section 12(c) of the UK Addendum, the Parties submit to the jurisdiction and venue stipulated in the Agreement.
- Performance Data
Customer acknowledges that Runpod may collect, use, and disclose Performance Data for its own business purposes, including: (i) accounting, tax, billing, audit, and compliance; (ii) providing, improving, developing, optimizing, and maintaining the Services; (iii) investigating fraud, spam, or wrongful or unlawful use of the Services; and/or (iv) as otherwise permitted or required by applicable law.
In respect of such Processing, Runpod independently determines the purposes and means thereof and shall: (a) comply with applicable Data Protection Laws; (b) Process such data as described in Runpod's privacy notices (including at https://www.runpod.io/legal/privacy-policy, as updated from time to time); and (c) where possible, apply technical and organizational safeguards to any relevant Personal Data that are no less protective than the security measures set out in this DPA. For the avoidance of doubt, this DPA shall not apply to Runpod's Processing of Performance Data, and Performance Data does not constitute Customer Personal Data.
Attachment 1:
Technical and Organizational Measures (“TOMs”)
Action Description
Technical & Organizational Measures
Pseudonymization and Anonymization
Runpod employs tools to selectively anonymize certain data, which may include Personal Data.
Encryption
Encryption is used for data in transit and at rest, and this encryption is provided by Amazon Web Services Inc. (“AWS”) and Secure Cloud data centers, approved Sub-Processors (see Attachment 2). Runpod also encrypts data in transit.
Confidentiality
All Runpod Employees are required to sign a confidentiality agreement and accept company policies and procedures upon hire.
Integrity
The Services provide administrative controls for Customer to control who can access files within their firm. Runpod does not have these rights.
An access control policy and procedures are in place to review access control lists.
Runpod conducts periodic risk assessments to identify, rank, treat, and manage risks to an acceptable level.
Availability
Monitoring is performed through capacity management monitoring solutions.
Quality assurance processes are in place and under regular review, to mitigate against potential downtime.
Resilience of Processing Systems
The Services are hosted on AWS platform and Secure Cloud data centers. These hosting platforms are ISO 27001 and SOC 2 Type 2 certified for security, confidentiality, integrity, privacy and availability.
Restoration
Backup policy and procedures are in place, with daily automated backup reports to ensure restoration is achievable. Reports are monitored by an operational team.
An Information Security Incident Response Policy & Procedure is in place to address actual and potential Data Breaches.
Auditing/Testing
Regular audits and assessments take place for purposes of SOC 2 compliance. In addition, from time to time Runpod engages with a third party, for penetration testing services and vulnerability assessments.
Detection and monitoring
Runpod deploys firewalls and threat detection services to monitor, filter, and protect Runpod systems.
Security is incorporated into the software development lifecycle and change processes.
Additional security and compliance features related to the data center (DC) configuration for the Serverless (SLS) setup
For services utilizing Serverless (SLS) infrastructure, Runpod enables the configuration of deployments so that endpoints are isolated to specific data centers that meet defined compliance standards. This includes the ability to restrict deployments to data centers that are subject to specific regulatory requirements (e.g., HIPAA) or that otherwise satisfy applicable regulatory and contractual obligations. Customers are responsible for configuring their workloads to deploy to data centers that meet their compliance needs.
Runpod shall, upon request, advise the Controller on which data center options are available and appropriate based on the Controller’s compliance obligations.
Additional information
In addition to the measures mentioned above, Runpod implements and maintains robust technical and organizational measures to ensure a high level of data security and compliance. These include:
- Certification under SOC 2 Type II;
- End-to-end encryption of data in transit and at rest;
- Strict role-based access controls, regular staff security training, and established incident response plans;
- Real-time monitoring and automated workload management systems to maintain security and performance integrity.
Attachment 2:
Runpod’s Sub-Processors
Sub-Processor
Purpose of Processing
Amazon Web Services Inc.
Services and Customer Data is processed with Runpod licensed software, on Amazon Web Services Inc.’s infrastructure.
Google Workspace - Google Inc.
A collection of cloud computing, productivity and collaboration tools, software and products, to enable real-time collaboration between
Runpod teams including, document creation, collection, and storage.
Google Cloud - Google Inc.
A collection of cloud computing, productivity and collaboration tools, software and products, to enable real-time collaboration between
Runpod teams and provide advance tools for scalability, security and performance.
HubSpot Inc.
A customer relationship management (CRM) platform for Runpod and its customers, prospects, and partners used by Runpod’s Sales and Marketing team to communicate with customers.
Stripe Inc.
A cloud-based business platform for invoicing and financial account management. Data collected, stored and processed is specific to fulfilling business services in performance of contracts.
BetterStack Inc.
A log monitoring platform, technical service and Runpod application logs are sent to BetterStack for search, analysis, and system monitoring. Sensitive data fields are masked such as usernames and emails, while some low sensitivity data such as IP and Host are captured directly.
Cloudflare Inc.
A content delivery platform that improves network performance, security and reliability to customers by caching static content and optimizing web traffic
PlanetScale
A cloud-based database hosting platform that has high availability, scalability, and performance for large-scale data operations managed by Runpod’s engineering team.
Docker Inc.
A containerization service that enables scalable and efficient application delivery by managing applications in an isolated environment and streamlining development workflows.
Datadog Inc.
A SIEM platform that provides application monitoring, infrastructure monitoring, log management, and alerting to ensure system reliability and operational efficiency.
Clerk Inc.
A user authentication and authorization platform that supports processes such as sign ups, logins, customer profile management, and session management.
Tinybird
A platform that provides real-time data processing and analytics services that enables the ingestion, transformation and querying of large data streams, which allows Runpod to derive actionable insights and build APIs from real-time data.
DigitalOcean LLC.
A cloud infrastructure and hosting platform that manages virtual servers, storage, and networking resources enabling Runpod to deploy, scale, manage applications and services.
Snowflake Inc.
A cloud-based data warehouse that stores, manages, and analyses structured and semi-structured data scalably and securely.
Attachment 3:
Standard Contractual Clauses
The Standard Contractual Clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council, as approved by Commission Implementing Decision (EU) 2021/914 of 4 June 2021 (as may be amended, superseded, or replaced), are hereby incorporated by reference into this DPA as if set out in full herein.
For the purposes of the Standard Contractual Clauses:
- Module Two (Controller to Processor) shall apply;
- in Clause 7, the optional docking clause shall apply;
- in Clause 9(a), Option 2 (general written authorization) shall apply, and the time period for prior notice of Sub-Processor changes shall be as set out in Section 8 of this DPA;
- in Clause 11(a), the optional wording shall not apply;
- in Clause 13, the competent Supervisory Authority shall be the authority of the EU Member State in which Customer is established in the EEA;
- in Clause 17, Option 1 shall apply and the Standard Contractual Clauses shall be governed by the law of Ireland;
- in Clause 18(b), disputes shall be resolved before the courts of Ireland; and
- the Appendix Information shall be completed as follows:
Annex I.A (List of Parties) as set out in the preamble and signature block of this DPA;
Annex I.B (Description of Transfer) as set out in Section 3 of this DPA;
Annex I.C (Competent Supervisory Authority), the Supervisory Authority of the EU Member State in which Customer is established;
Annex II (Technical and Organizational Measures), as set out in Attachment 1 to this DPA; and
Annex III (List of Sub-Processors), as set out in Attachment 2 to this DPA.
Attachment 4:
International Data Transfer Addendum to the EU Commission Standard Contractual Clauses
The International Data Transfer Addendum to the EU Commission Standard Contractual Clauses (Version B1.0), as issued by the ICO and in force from 21 March 2022 (as may be amended, superseded, or replaced) (the "UK Addendum"), is hereby incorporated by reference into this DPA as if set out in full herein. For the purposes of the UK Addendum:
- Table 1 (Parties) shall be completed as follows: the start date shall be the Effective Date; the Exporter shall be Customer and the Importer shall be Runpod, with parties' details and key contacts as set out in the preamble and signature block of this DPA;
- Table 2 (Selected SCCs, Modules and Selected Clauses): the Addendum EU SCCs shall be the Standard Contractual Clauses incorporated by reference in Attachment 3 to this DPA, including the elections specified therein;
- Table 3 (Appendix Information) shall be completed as follows: Annex 1A (List of Parties) — as set out in the preamble and signature block of this DPA; Annex 1B (Description of Transfer) — as set out in Section 3 of this DPA; Annex II (Technical and Organisational Measures) — as set out in Attachment 1 to this DPA; and Annex III (List of Sub-Processors) — as set out in Attachment 2 to this DPA;
- Table 4 (Ending this Addendum when the Approved Addendum Changes): the Importer may end this Addendum in accordance with Section 19 of the Approved Addendum;
- The UK Addendum shall be governed by the laws of England and Wales and any dispute arising from it shall be resolved by the courts of England and Wales; and
- the competent supervisory authority for the purposes of the UK Addendum shall be the ICO.
Attachment 5:
Switzerland Addendum
Modified EU SCCs. The Parties agree that Restricted Transfers from Switzerland are made pursuant to the Standard Contractual Clauses with the following modifications:
The terms “General Data Protection Regulation” or “Regulation (EU) 2016/679” as utilized in the EU SCCs shall be interpreted to include the FADP with respect to Restricted Transfers subject to the FADP.
Clause 13 of the Standard Contractual Clauses is modified to provide that the FDPIC shall have authority over the Restricted Transfers governed by the FADP and the appropriate EEA Supervisory Authority shall have authority over Restricted Transfers governed by the EU GDPR. Subject to the foregoing, all other requirements of Section 13 shall be observed.
The term “EU Member State” as utilized in the Standard Contractual Clauses shall not be interpreted in such a way as to exclude Data Subjects in Switzerland from exercising their rights in their place of habitual residence in accordance with Clause 18(c) of the Standard Contractual Clauses.
Competent supervisory authority. Where Customer is established in Switzerland or falls within the territorial scope of application of the FADP, the FDPIC shall act as competent supervisory authority insofar as the relevant Restricted Transfer is governed by the FADP.
Attachment 6:
State Privacy Laws Addendum
In this Attachment 6, the terms “business,” “business purpose,” “commercial purpose,” “consumer,” “sell,” “share,” and “service provider” shall have the respective meanings given thereto in the CCPA; and “personal information” shall mean Customer Personal Data that constitutes “personal information” as defined in and that is subject to the State Privacy Laws.
- The business purposes and services for which Runpod is Processing personal information are for Runpod to provide the Services to and on behalf of Customer as set forth in the Agreement.
- It is the Parties’ intent that with respect to any personal information, Runpod is a service provider. Runpod (a) acknowledges that personal information is disclosed by Customer only for limited and specific purposes described in the Agreement; (b) shall comply with applicable obligations under the State Privacy Laws and shall provide the same level of privacy protection to personal information as is required by the State Privacy Laws; (c) agrees that Customer has the right to take reasonable and appropriate steps under and subject to Section 13 (Audits) of the DPA to help ensure that Runpod’s use of personal information is consistent with Customer’s obligations under the State Privacy Laws; (d) shall notify Customer in writing of any determination made by Runpod that it can no longer meet its obligations under the State Privacy Laws; and (e) agrees that Customer has the right, upon notice, including pursuant to the preceding clause, to take reasonable and appropriate steps to stop and remediate unauthorized use of personal information.
- Runpod shall not (a) sell or share any personal information; (b) retain, use or disclose any personal information for any purpose other than for the business purposes specified in the Agreement, including retaining, using, or disclosing the personal information for a commercial purpose other than the business purpose specified in the Agreement, or as otherwise permitted by State Privacy Laws; (c) retain, use or disclose the personal information outside of the direct business relationship between Runpod and Customer; or (d) combine personal information received pursuant to the Agreement with personal information (i) received from or on behalf of another person, or (ii) collected from Runpod’s own interaction with any consumer to whom such personal information pertains except as and to the extent necessary as part of Runpod’s provision of the Services.
- Runpod shall implement reasonable security procedures and practices appropriate to the nature of the personal information received from, or on behalf of, Customer, in accordance with Section 7 (Technical & Organizational Measures) of the DPA.
- When Runpod engages any Sub-Processor, Runpod shall notify Customer of such Sub-Processor engagements in accordance with Section 8 (Sub-Processing) of the DPA and that such notice shall satisfy Runpod’s obligation under the State Privacy Laws to give notice of and an opportunity to object to such engagements.
- Runpod agrees that Customer may conduct audits, in accordance with Section 13 of the DPA, to help ensure that Runpod’s use of personal information is consistent with Runpod’s obligations under the State Privacy Laws.
- The parties acknowledge that Runpod’s retention, use and disclosure of personal information by Customer’s instructions documented in the Agreement and DPA are integral to Runpod’s provision of the Services and the business relationship between the Parties.
Attachment 7:
Brazil Addendum
1. Scope and Applicability
This Attachment 7 applies where the transfer of Customer Personal Data is subject to the Brazilian General Data Protection Law (Lei Geral de Proteção de Dados Pessoais, Law No. 13.709/2018, as amended) ("LGPD"). For the purposes of the LGPD and this Attachment 7, references to "Data Protection Laws" in the DPA shall be construed to include the LGPD to the extent applicable.
2. Brazilian Standard Contractual Clauses
For any Restricted Transfer of Customer Personal Data from Brazil to a country that does not provide an equivalent level of protection as required under the LGPD, the Processor shall ensure that such transfer is protected by implementing the Brazilian Standard Contractual Clauses ("Brazilian SCC") issued by the Brazilian National Data Protection Authority (Autoridade Nacional de Proteção de Dados, "ANPD") pursuant to Resolution CD/ANPD No. 19/2024 (as may be amended, superseded, or replaced from time to time), which are hereby incorporated by reference into this DPA as if set out in full herein. The Brazilian SCC are available at the ANPD's official website.
3. Roles of the Parties
For the purposes of the Brazilian SCC:
- the Controller (Customer) shall assume the role of Data Exporter, as defined in the Brazilian SCC; and
- the Processor (Runpod) shall assume the role of Data Importer, as defined in the Brazilian SCC.
4. Elections under the Brazilian SCC
The following elections apply to the Brazilian SCC incorporated herein
- Clause 3 (Onward Transfers): Option 3.1A shall apply.
- Clause 4 (Responsibilities of the Parties): Option 4.1A shall apply. In accordance with Option 4.1A, the Data Exporter (Controller) shall be responsible for complying with the obligations set out in the corresponding list under the Brazilian SCC.
5. Consistency with the DPA
The terms of this Attachment 7 are supplemental to, and shall be read in conjunction with, the DPA. In the event of any conflict between this Attachment 7 and the remainder of the DPA (including any other Attachment) in respect of the Processing of Customer Personal Data subject to the LGPD, this Attachment 7 shall prevail. The Annexes and Appendix Information required under the Brazilian SCC shall be completed by reference to the corresponding information set out in this DPA, including:
- the parties' details as set out in the preamble and signature block of this DPA;
- the description of the transfer and Processing activities as set out in Section 3 of this DPA;
- the technical and organizational measures as set out in Attachment 1 to this DPA; and
- the list of Sub-Processors as set out in Attachment 2 to this DPA.
6. Governing Law and Supervisory Authority
This Attachment 7 and the Brazilian SCC incorporated herein shall be governed by Brazilian law. The competent supervisory authority for the purposes of the Brazilian SCC shall be the ANPD.