SmartBear Data Processing Addendum
1. Purpose
This Data Processing Addendum (this “Addendum”) forms a part of, and is incorporated by reference into, the SmartBear Terms of Use (the “Agreement”), entered into between SmartBear Software, Inc., and its subsidiaries and affiliates (collectively, “SmartBear”) and you or the entity that you represent (the “Customer”) (together, the “Parties”).. Notwithstanding anything to the contrary in the Agreement, if there is a conflict between this Addendum and the Agreement, this Addendum will control.
2. Definitions
Capitalized terms used but not defined have the meaning given in the Agreement. Other terms in this Addendum, which are not defined in the Agreement or this Addendum, shall have meanings consistent with any corresponding terms in Data Protection Law.
- “Data Protection Law” means any applicable law relating to data security, data protection and/or privacy including, without limitation, Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to processing of personal data and the free movement of that data ( “EU GDPR” ), Retained Regulation (EU) 2016/679 (the “UK GDPR” , and together with the EU GDPR, the “GDPR” ) and the UK Data Protection Act of 2018, and the California Consumer Privacy Act (Cal. Civ. Code § 1798.100 et. seq.) (“CCPA”), and any implementing, derivative or related legislation, rule, regulation, and regulatory guidance, as amended, extended, repealed and replaced, or re-enacted.
- “Licensed Software” means the object code version of the SmartBear software installed and operated by Customer on Customer’s own infrastructure or designated environment, as specified in an Order. Licensed Software includes any updates made available by SmartBear, but excludes any third-party products, services, applications, or APIs.
- “Personal Data” means any information relating to, that describes, is reasonably capable of being associated with, or could reasonably be linked to an identified or identifiable natural person (“Data Subject”), and which is Processed by SmartBear on behalf of Customer in accordance with the Agreement (including any restrictions therein on Customer’s submission of data to the Solution or use of the Solution). An identifiable natural person is one who can be identified, directly or indirectly, in particular by referencing an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.
- “Personal Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data.
- “Process”, “Processing” or “Processed” means any operation or set of operations which is performed upon Personal Data whether or not by automatic means, including collecting, recording, organizing, storing, adapting or altering, retrieving, consulting, using, disclosing, making available, aligning, combining, blocking, erasing and destroying Personal Data.
- “Solution” or “Solutions” means the SmartBear-provided SaaS and/or Licensed Software which is identified as requiring the processing of Personal Data in the SmartBear Solution Specific Terms and set forth in Schedule 1 hereto.
- “Solution Specific Terms” means the terms which are located currently at https://smartbear.com/legal/solution-specific-terms/ , as updated from time to time.
- “Standard Contractual Clauses” means, with respect to (i) the UK GDPR, the standard contractual clauses (controller to processor module) set out in European Commission Decision 2021/914 of 4 June 2021 as modified by the UK Addendum to the EU standard contractual clauses (effective 21 March 2022), and (ii) the EU GDPR, the standard contractual clauses (controller to processor module) set out in European Commission Decision 2021/914 of 4 June 2021, in each case as amended, replaced, or superseded from time to time.
- “Subprocessor” means any third party which Processes Personal Data on behalf of SmartBear.
3. Scope; Role of the Parties
- This Addendum applies only to the extent Personal Data subject to Data Protection Laws is Processed by SmartBear in accordance with the Agreement. The Parties acknowledge and agree that for purposes of the GDPR, with regard to the Processing of Personal Data, (i) Customer is the Data Controller, (ii) SmartBear is a Data Processor, and (iii) SmartBear may engage Subprocessors pursuant to the requirements set forth in Section 6 below. Further details of the Processing activities for the Solutions under this Addendum are set forth in Schedule 1.
- Customer represents and warrants that it has a legal basis for Processing Personal Data in accordance with applicable Data Protection Law, and the authority and right, including consent where required, to lawfully transfer Personal Data to SmartBear for Processing in accordance with this Addendum. Customer shall comply with all applicable Data Protection Laws in connection with the Personal Data, including in connection with providing all required notices and obtaining all required consents regarding the Processing and transfer of Personal Data.
4. Obligations of SmartBear
- Limitations on Use; Instructions. SmartBear shall, and shall require that Subprocessors shall, Process Personal Data only: (i) on behalf of Customer and in accordance with Customer’s documented instructions, including with regard to transfers of Personal Data to a third country or an international organization; (ii) when required to do so by applicable law to which SmartBear is subject, in which case SmartBear will inform Customer of that legal requirement before Processing unless prohibited by applicable law; and (iii) in compliance with this Addendum and applicable Data Protection Law. For purposes of this Addendum, Customer’s documented instructions consist of the Agreement, applicable Orders, this Addendum, and Customer’s use and configuration of the Solutions. Customer is responsible for ensuring its documented instructions comply with applicable Data Protection Law and for determining whether the Solutions are appropriate for Customer’s intended Processing.
- Security. SmartBear has implemented and will maintain commercially reasonable technical and organizational measures, as further described in Annex II, to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. Having regard to the state of the art, the costs of implementation, and the nature, scope, context and purposes of the Processing, SmartBear shall ensure a level of security appropriate to the risk. SmartBear may update the technical and organizational measures from time to time provided that such updates do not materially diminish the overall security of the Solutions.
- Confidentiality. SmartBear will treat all Personal Data as confidential information in accordance with the Agreement. SmartBear will take reasonable steps to ensure that its personnel who have access to the Personal Data are obligated to keep such Personal Data confidential.
- Breach Response. SmartBear shall notify Customer without undue delay after becoming aware of a Personal Data Breach, via email to Customer’s designated account owner, administrator, or security contact unless otherwise agreed in writing, and SmartBear shall take reasonable steps to prevent any further Personal Data Breach and to mitigate any resulting damage. SmartBear shall provide Customer with prompt cooperation and assistance in relation to any notifications that Customer is required to make as a result of the Personal Data Breach. Upon written request, SmartBear shall also provide Customer with reasonable assistance, taking into account the information available to SmartBear, in relation to any data protection impact assessment or regulatory consultation that Customer is legally required to make in respect of Personal Data Processed through the Solutions.
- Data Subject/Supervisory Authority Request. Taking into account the nature of the Processing, SmartBear will provide Customer with reasonable cooperation and assistance in relation to any complaint, communication or request received from a Data Subject or a data protection supervisory authority relating to Personal Data Processed through the Solutions. Where a request is received directly by SmartBear and identifies the relevant Customer, SmartBear will, unless prohibited by law, promptly redirect or relay the request to Customer without substantively responding, except to the extent necessary to identify the relevant Customer or as otherwise required by applicable law. SmartBear’s obligations under this Section apply only to the extent Customer cannot address the request through the Solutions, including available search, export, deletion, or data-access API functionality.
- Audit and Certifications. To the extent required by applicable Data Protection Laws, and upon Customer’s reasonable written request (not less than sixty (60) days in advance) and at mutually agreed upon times no more than once in any 12 month period (unless a Personal Data Breach has occurred or a supervisory authority requires an additional audit), and subject to the confidentiality obligations set forth in the Agreement, SmartBear shall permit Customer to take reasonable and appropriate steps to help ensure the Processing of Customer Personal Data is consistent with SmartBear’s obligations by allowing reasonable assessments to be conducted by Customer or a mutually agreed upon independent assessor to assess SmartBear’s compliance with its obligations, and the physical, technical and organizational measures in support of SmartBear’s obligations using an appropriate and accepted control standard or framework and procedure for the assessment. Notwithstanding anything to the contrary, no audit shall be undertaken unless or until Customer has requested, and SmartBear has provided, documentation pursuant to this Section and Customer reasonably determines that an audit remains necessary to demonstrate material compliance with the obligations laid down in this Addendum. SmartBear shall make available to Customer, upon request, copies of relevant third-party audit reports or certifications (such as SOC 2 or ISO 27001) to demonstrate compliance. Without limiting the generality of any provision in the Agreement, Customer shall employ the same degree of care to safeguard information disclosed by SmartBear pursuant to this Section 4 of this Addendum that it uses to protect its own confidential and proprietary information and in any event, not less than a reasonable degree of care under the circumstances, and Customer shall be liable for any improper disclosure or use of information disclosed by SmartBear pursuant to this Section 4 of this Addendum by Customer or its agents.
- Return or Disposal. During the subscription term, Customer may export or delete certain Personal Data using standard Solution functionality, including dashboard features and APIs where available for the applicable Service. Upon expiration or termination of the order term, and subject to the Agreement and applicable law, SmartBear shall, upon Customer’s written request made within sixty (60) days after termination, either (i) provide Customer with a commercially reasonable opportunity to export Customer Data then retained in active systems, or (ii) securely delete or anonymize Personal Data, provided that SmartBear may retain Personal Data in backup media, logs, support systems, or records only to the extent required by applicable law, for so long as permitted by applicable law and subject to the confidentiality and security obligations of this Addendum.
5. Obligations of Customer.
- Customer is responsible for: (i) determining whether the Solutions are appropriate for Customer’s intended Processing; (ii) providing all required notices and obtaining all required consents; (iii) deciding what data Customer’s applications and users send to the Solution; (iv) configuring available privacy, filtering, and redaction controls appropriately; and (v) ensuring that Customer does not submit Restricted Information or special category personal data except as expressly permitted in the Agreement and this Addendum.
- Secure Use of the Solutions. Customer is responsible for configuring and using the Solutions in accordance with applicable Data Protection Law and the Agreement, including determining what data Customer applications, websites, mobile apps, and users send to the Solution, and consulting the applicable Solution documentation at https://support.smartbear.com/documentation/ , as updated from time to time. Customer acknowledges that the Solutions are not intended for the processing of Restricted Information or special category personal data except as expressly permitted in the Agreement and this Addendum.
6. Subprocessors.
- Customer hereby generally authorizes SmartBear to appoint Subprocessors for purposes of Processing Personal Data pursuant to the Agreement.
- Upon Customer’s request, or as otherwise required by applicable Data Protection Laws, SmartBear shall make available current information about its Subprocessors that may Process Personal Data for the Solutions. SmartBear may satisfy this obligation by maintaining such information at https://smartbear.com/legal/smartbear-subprocessors/ or a successor URL, which may also provide a mechanism for subscribing to updates.
- SmartBear will provide notice of the appointment of a new Subprocessor that will Process Personal Data for the Solutions by updating the foregoing URL and/or the related subscription mechanism before the new Subprocessor commences such Processing. If Customer can reasonably show that the appointment of a new Subprocessor will have a material adverse effect on Customer’s ability to comply with applicable Data Protection Laws, then Customer must promptly notify SmartBear in writing within fifteen (15) business days of receiving such notice of its reasonable basis for objection. Upon receipt of Customer’s written objection, Customer and SmartBear will work together without unreasonable delay to agree upon an alternative arrangement. If a mutually acceptable and reasonable alternative arrangement is not found, then Customer may terminate the Agreement only with respect to those Solutions that cannot be provided by SmartBear without the use of the new Subprocessor. Unless prohibited by applicable Data Protection Laws, in the event of such early termination by Customer, SmartBear may retain or require payment under the Agreement through the end of Customer’s current contract term for the terminated Solution.
- In the event SmartBear engages Subprocessors in connection with the Solution, SmartBear shall place the same or similar obligations as those in this Addendum on such Subprocessors, or such other obligations as required by applicable Data Protection Law, and shall remain fully liable to Customer for the acts or omissions of such Subprocessors, as if they were the acts or omissions of SmartBear.
7. International Transfers of Personal Data.
- The parties acknowledge that transfers of Customer Personal Data to SmartBear that are subject to an applicable adequacy decision do not require a separate approved transfer mechanism. If a transfer of Customer Personal Data to SmartBear is not subject to an applicable adequacy decision (a “Restricted Transfer”), the Restricted Transfer is made in accordance with the following.
-
Where a Restricted Transfer is made from the EEA, the SCCs
are incorporated into this DPA and apply to the transfer as
follows:
- Module Two (Controller to Processor) of the EU Standard Contractual Clauses shall apply,
- Clause 7 (docking clause) shall not apply,
- Clause 9 shall apply using Option 2 (general written authorization) with the notice period for Subprocessor changes as stated in Section 6 of this Addendum,
- Clause 11 optional language shall not apply,
- Clause 17 shall designate Irish law,
- Clause 18(b) disputes shall be resolved before the courts of Ireland, Annex I shall be completed with the information in Schedule 1,
- Annex II shall be completed with the information in Schedule 2, and
- Annex III of the SCCs is completed with the information in the Subprocessors List.
- Where a Restricted Transfer is made from the UK, the UK Transfer Addendum is incorporated into this DPA and applies to the transfer. The UK Transfer Addendum is completed with the information in Section 7(b), the Subprocessors List, and Schedules 1 and 2 to this DPA; and both “Importer” and “Exporter” are selected in Table 4.
-
Where a Restricted Transfer is made from Switzerland, the
SCCs are incorporated into this DPA and apply to the
transfer as modified in Section 7(b), except that:
- in Clause 13, the competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner;
- references to “Member State” in the SCCs refer to Switzerland, and data subjects located in Switzerland may exercise and enforce their rights under the SCCs in Switzerland; and
- references to the “General Data Protection Regulation,” “Regulation 2016/679,” and “GDPR” in the SCCs refer to the Swiss Federal Act on Data Protection (as amended or replaced).
- Where a Restricted Transfer is made from Brazil, the parties shall comply with the transfer requirements of the Brazilian General Data Protection Law (Lei Geral de Proteção de Dados, “LGPD”), including entering into standard contractual clauses or other transfer mechanisms as adopted by the Brazilian National Data Protection Authority (ANPD), when and as required.
- To the extent SmartBear may lawfully rely on another recognized transfer mechanism for a particular transfer, including an adequacy decision, certification, or other lawful transfer framework, SmartBear may do so.
- In the event of inconsistencies between the provisions of the Standard Contractual Clauses and this Addendum or other agreements between the Parties, the Standard Contractual Clauses shall take precedence, but only with respect to the relevant cross-border transfer.
- The information set forth in Schedule 1 constitutes the information required to be included in the schedules and appendices to the Standard Contractual Clauses, and the Parties’ signatures to this Addendum are deemed to also constitute signature of the Standard Contractual Clauses to the extent separate execution is required.
8. CCPA Compliance
To the extent applicable and pursuant to the CCPA, with respect to “personal information” as defined by the CCPA which SmartBear may Process in connection with its performance of the Solutions, SmartBear agrees and certifies that it will not:
- Sell, share, rent, release, disclose, disseminate, make available, transfer, or otherwise communicate orally, in writing, or by electronic or other means, such personal information to another business or a third party for monetary or other valuable consideration; or
- Retain, use, disclose, collect, sell, share, use, or otherwise process such personal information (i) for any purpose other than for the specific purpose of, and as necessary for, performing services for Customer pursuant to the Agreement, or (ii) as otherwise permitted by the CCPA. SmartBear further agrees to cooperate and assist Customer in fulfilling and complying with any consumer rights request pursuant to the CCPA.
9. Legal Requests
Unless prohibited by applicable law, in the event that SmartBear is required by law, court order, warrant, subpoena, or other legal judicial process (“Legal Request”) to disclose any Personal Data to any person or entity other than Customer (including, without limitation, pursuant to any US government surveillance order of which SmartBear is aware), SmartBear shall notify Customer promptly and shall provide all reasonable assistance to Customer, based on the information available to SmartBear and at Customer’s cost, to enable Customer to respond or object to, or challenge, any such Legal Requests. SmartBear shall not disclose Personal Data pursuant to a Legal Request unless it is required to do so under applicable law and has otherwise complied with the obligations in this Section.
10. Miscellaneous
The Parties acknowledge and agree that the limitations and exclusions of liability set forth in the Agreement shall also apply with respect to this Addendum.
Upon termination of the Agreement, SmartBear’s relevant obligations under this Addendum shall survive to the extent SmartBear continues to Process Personal Data. To the extent a conflict exists between this Addendum and the Agreement, the terms of this Addendum shall prevail. The Parties agree that this Addendum may be amended only by written agreement between the Parties.
Annex I
A. List of Parties
Data exporter(s):
Name: Customer
Address: As set forth in the Agreement.
Contact person’s name, position and contact details: Customer’s Designated
POC.
Activities relevant to the data transferred under these Clauses: The
provision of the Solutions.
Role (controller/processor): Controller.
Data importer(s):
Name: SmartBear Software, Inc.
Address: 450 Artisan Way, 4th Floor, Somerville, MA 02145
Contact person’s name, position and contact details: Privacy Office,
legal@smartbear.com
Activities relevant to the data transferred under these Clauses: The
provision of the Solutions.
Role (controller/processor): Processor.
B. Description of Transfer
Categories of data subjects whose personal data is transferred
The categories of data subjects whose personal data is transferred under the Clauses are individuals whose personal data is included within Customer Personal Data, including but not limited to employees and other personnel of Customer.
Categories of personal data transferred
The categories of personal data transferred under the Clauses are name, login information, and any personal data included within Customer Personal Data that Customer uploads to or makes accessible to SmartBear through the Solutions.
Sensitive data transferred (if applicable) and applied restrictions or safeguards that fully take into consideration the nature of the data and the risks involved, such as for instance strict purpose limitation, access restrictions (including access only for staff having followed specialised training), keeping a record of access to the data, restrictions for onward transfers or additional security measures.
To the parties’ knowledge, no sensitive data is transferred.
The frequency of the transfer (e.g. whether the data is transferred on a one-off or continuous basis).
Continuous.
Nature of the processing
The provision of the Solutions.
Purpose(s) of the data transfer and further processing
The provision of the Solutions.
The period for which the personal data will be retained, or, if that is not possible, the criteria used to determine that period
Data importer will retain personal data in accordance with the Addendum.
C. Competent Supervisory Authority
The supervisory authority set out in Clause 7 of this DPA.
Annex II
Technical and Organizational Security Measures
This Security Exhibit describes the administrative, technical, and physical controls applicable to the SaaS. For the avoidance of doubt, this documentation does not apply to any Betas or free trials of the SaaS made available by SmartBear. Any capitalized terms used but not defined herein will have the meanings ascribed to them in the Agreement.
SmartBear shall implement and maintain an information security program with reasonable organizational, administrative, and technical controls aligned with recognized industry standards and appropriate to the nature and scope of SmartBear’s activities and services. Among other standards, SmartBear has aligned its security program with the Center for Internet Security’s (CIS) 18 Critical Security Controls (the “ Controls ”). The following sections describe how SmartBear has aligned its security program to the Controls.
-
Inventory and Control of Enterprise Assets
- SmartBear will implement and maintain an asset management program in accordance with industry standards. SmartBear will tag all SmartBear-controlled servers and workstations used to store or process Customer Data (each, an “Endpoint”) and maintain an up-to-date inventory of assets.
-
Inventory and Control of Software Assets
- SmartBear will actively manage (inventory, track, and correct) all software (operating systems and applications) on the network so that only authorized software is installed and can execute, and that unauthorized and unmanaged software is found and prevented from installation or execution.
-
Data Protection
- SmartBear will maintain processes and technical controls to identify, classify, securely handle, retain, and dispose of data. SmartBear’s contractual commitments regarding data privacy are contained in the DPA.
- SmartBear will store and transmit Customer Data using industry standard encryption mechanisms with no less than a 128-bit key for symmetric encryption and a 2048 (or larger) bit key length for asymmetric encryption.
- SmartBear will provide Customer a mechanism within the SaaS that Customer can use to delete the Customer Data. If Customer is unable to delete the Customer Data, SmartBear will, subject to the terms of the Agreement and applicable law, delete or, at Customer’s cost, return the Customer Data upon Customer’s written request, except for backups. In the event that deletion of the Customer Data would be unduly burdensome, SmartBear will protect the Customer Data as set forth in the confidentiality section of the Agreement.
-
Secure Configuration of Enterprise Assets and Software
-
SmartBear will configure assets by:
- encrypting Endpoints in accordance with industry standards;
- enabling firewalls on all Endpoints;
- scanning Endpoints on at least a weekly basis and remediate findings in accordance with SmartBear’s vulnerability management policies and procedures;
- Requiring employees to use a secure web browser when accessing SmartBear’s production environment;
- using industry standards for password rotation, account lock, failed attempts, use of default passwords, password age, and password complexity;
- applying operating system (OS) and application security patches in accordance with industry practices.
-
SmartBear will configure assets by:
-
Account Management
-
SmartBear will implement policies, procedures, and
logical controls that are designed to:
- limit access to its information systems to properly authorized persons;
- prevent personnel and others who should not have access from obtaining access; and
- remove access in a timely manner in the event of a change in job responsibilities or job status.
-
SmartBear will implement policies, procedures, and
logical controls that are designed to:
-
Access Control Management
- SmartBear will implement controls designed to ensure that only those personnel who have a need to know will have access to Customer Data and that any SmartBear personnel who are granted access to any Customer Data will only do so based on least-privilege principles.
- SmartBear will implement and maintain a remote access policy for its employees and contractors. When remote connectivity to SmartBear-controlled network(s) is required, SmartBear will use VPN servers for remote access and multi-factor authentication (MFA) for accounts with privileged or elevated access rights to systems or applications hosting or processing Customer Data.
-
Continuous Vulnerability Management
-
SmartBear will implement a vulnerability management
program in accordance with industry standards. As
part of the program, SmartBear will:
- Use reasonable and appropriate efforts to assess and remediate vulnerabilities that could compromise the data, systems, or critical functioning of the information technology infrastructure that impact SmartBear’s external-facing environments or that impact the SaaS;
- Conduct periodic vulnerability scans of its external facing environments;
- Ensure critical and high severity vulnerabilities identified as part of the scans/testing performed by SmartBear will be remediated in accordance with SmartBear’s vulnerability management policies and procedures; and
- Ensure critical, and high patches are implemented in accordance with its vulnerability management program (provided that, in the case of third-party software, a stable patch is made available by the applicable supplier).
-
SmartBear will implement a vulnerability management
program in accordance with industry standards. As
part of the program, SmartBear will:
-
Audit Log Management
- SmartBear will generate and retain logs that record activity with respect to systems used in providing the SaaS and will protect such logs against unauthorized access, modification, and accidental or deliberate destruction.
-
Email and Web Browser Protections
- SmartBear will implement web filters to block access to malicious websites on Endpoints used to provide the SaaS to Customer.
-
Malware Defenses
- SmartBear will deploy and maintain reasonable industry standard antivirus/malware controls on applicable Endpoints involved in providing the SaaS to Customer. SmartBear will configure the antivirus controls to perform periodic endpoint evaluations and SmartBear will use commercially reasonable efforts to remediate the findings.
-
Data Recovery
- SmartBear will perform backups of the Customer Data on an hourly basis. Backups are encrypted and stored remotely.
- SmartBear will maintain business continuity and disaster recovery plans in accordance with industry practices relevant to the SaaS. SmartBear will perform testing, conduct exercises, and provide training to relevant employees on its business continuity and disaster recovery plans.
-
Network Infrastructure Management
- SmartBear will establish, implement, and actively manage (track, report, correct) network devices, in order to prevent attackers from exploiting vulnerable network services and access points.
-
Network Monitoring and Defense
- SmartBear will use commercially reasonable efforts to secure networks by utilizing commercially available equipment and industry standard techniques, which may include firewalls, intrusion detection systems, intrusion prevention systems, web filtering, access control lists, and routing protocols on SmartBear-controlled networks used to process, store, transmit, or access Customer Data.
-
Security Awareness Skills and Training
- SmartBear will require annual security awareness and training programs for SmartBear employees that address their compliance with SmartBear’s security policies.
-
Service Provider Management
- SmartBear will use well-managed third-party cloud hosting providers (including, but not limited to Amazon Web Services, Microsoft Azure, and Google Cloud Platform) to host its SaaS. Further information on physical security and hosting infrastructure may be found at the applicable provider’s website.
-
Application Software Security
- SmartBear will manage the security life cycle of in-house developed, hosted, or acquired software to prevent, detect, and remediate security weaknesses before they can impact the enterprise.
-
Incident Response Management
- SmartBear will implement and maintain an incident response plan in accordance with industry standards which describes the processes and procedures that SmartBear follows to respond to, remediate, and resolve any compromise of the technical and organizational security measures of the SaaS that results in an actual compromise of Customer Data (“ Security Incident ”).
- In the event of a verified breach affecting Customer Data, SmartBear will notify Customer promptly following SmartBear’s confirmation of such breach. Such notification may be provided via email or other electronic means. SmartBear will promptly investigate the Security incident and take actions to remediate the effects of the Security Incident and mitigate any risks that may result from the Security Incident.
-
Penetration Testing
- On a periodic basis SmartBear will conduct third-party security testing on applications and infrastructure used to support the provision of the SaaS to Customer in order to identify security vulnerabilities. Subject to an appropriate confidentiality agreement, SmartBear will provide summary reports of such security testing to Customer upon Customer’s written request no more than once per calendar year.
Schedule 1 — Details of the Processing
BugSnag-Specific Details of the Processing of Personal Data
1. The nature and purpose of the Processing:
Processing by SmartBear and its Subprocessors necessary to provide the BugSnag Solution, including receiving, transmitting, hosting, storing, organizing, indexing, analyzing, displaying, searching, exporting, deleting, and otherwise making available to Customer diagnostic and operational data sent to BugSnag by or on behalf of Customer. The BugSnag Solutions include error and crash monitoring, session stability reporting, performance monitoring, distributed tracing, release and build management, symbol and source-map upload and processing, dashboards, notifications, APIs, support, and related account-administration features.
2. The duration of the Processing:
The duration of the Processing is for so long as SmartBear performs the services for Customer, or otherwise Processes Personal Data in connection with providing the Solutions under the Agreement, together with any additional period during which Personal Data remains in active systems, backups, logs, or support systems in accordance with the Agreement, SmartBear’s retention and backup practices, or applicable law.
3. The types of personal data:
Depending on Customer’s implementation, configuration, and use of the BugSnag Solution, Personal Data may include only the following categories of data submitted or made available by Customer or its Users: (i) account and administrator data, such as name, business email address, username, company or organization name, authentication or SSO identifiers, and invited-user information; (ii) support and billing contact data, such as name, business contact details, company, ticket or case content, and transaction metadata (excluding raw payment card data handled by payment processors); (iii) end-user identifiers and online identifiers that Customer chooses to send or permits the SDKs to capture, such as user ID, email, name, IP address, device ID, session ID, trace ID, and similar identifiers; (iv) application, device, browser, operating system, runtime, locale, network, and environment details; (v) request and event data, such as URLs, paths, query strings, headers, HTTP method, breadcrumbs, logs, metadata, error messages, stack traces, file paths, code context, release stage, application version, and session information; (vi) performance and tracing data, such as spans, trace attributes, timings, network-request telemetry, and reliability metrics; and (vii) build, source-control, symbolication, and source-map data uploaded by Customer, which may incidentally contain personal data in file paths, commit metadata, or other diagnostic content. SmartBear does not require Customer to submit special category personal data or other x Information to use BugSnag.
4. The categories of data subjects:
Personal Data may relate to the following categories of Data Subjects: Customer account owners, administrators, invited users, developers, operators, support contacts and other authorized users; Customer’s end users, prospects, website or mobile-app users, or other individuals whose information is included in error events, session data, performance traces, or related diagnostic data that Customer sends to BugSnag; and individuals identified in support tickets, release or build metadata, or other Customer-submitted content.
5. Special Categories of data or sensitive personal data:
Not applicable.