Data Processing Addendum
Last Updated: 30th September 2026
Version in Effect From: 30th September 2026
1. Introduction
This Data Processing Addendum ("Addendum") forms part of the Terms of Service, or any other agreement between Artifex Software, Inc., 39 Mesa Street, Suite 108A, San Francisco, CA 94129, US ("Company" or "Artifex") and the customer that has entered into that agreement ("Customer"), for the provision of the PDF.co services (the "Services"). That agreement is referred to in this Addendum as the "Agreement".
This Addendum applies whenever Company processes Personal Data as a Processor on Customer's behalf in providing the Services. Customer enters into this Addendum for itself and, where Applicable Data Protection Laws require it, on behalf of any of its Affiliates that are permitted to use the Services under the Agreement. In this Addendum, "Customer" includes those Affiliates unless stated otherwise.
No signature is required. This Addendum becomes legally binding automatically when Customer accepts or enters into the Agreement, and takes effect from the effective date of the Agreement ("Effective Date"). Customers who need a countersigned copy for their records may request one from the PDF.co Support Team.
2. Definitions
Capitalised terms not defined in this Addendum have the meanings given to them in the Agreement.
- "Affiliate" means any entity that directly or indirectly controls, is controlled by, or is under common control with a party, where "control" means ownership or control of more than 50% of the voting interests of the entity.
- "Applicable Data Protection Laws" means all privacy and data protection laws that apply to the processing of Personal Data under the Agreement, as amended or replaced from time to time, including the EU General Data Protection Regulation (EU) 2016/679 ("GDPR"), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection of 25 September 2020 ("FADP"), and the California Consumer Privacy Act ("CCPA"), in each case to the extent applicable.
- "Account Data" means Personal Data that Company processes as a Controller in connection with managing its relationship with Customer, such as account registration details, billing and payment information, and communications with Customer's personnel.
- "Controller" means a "controller" or "business" (or equivalent term) as defined under Applicable Data Protection Laws.
- "Customer Data" means the Personal Data contained in the content, files and other data that Customer or its users submit to the Services, and that Company processes on Customer's behalf.
- "Data Subject" means the identified or identifiable natural person to whom Personal Data relates, including a "consumer" under the CCPA.
- "Personal Data" means any information defined as "personal data", "personal information" or an equivalent term under Applicable Data Protection Laws.
- "Processing" means any operation performed on Personal Data, whether or not by automated means, including collection, recording, organisation, storage, adaptation, retrieval, use, disclosure, combination, restriction, erasure or destruction, and "process" has a corresponding meaning.
- "Processor" means a "processor" or "service provider" (or equivalent term) as defined under Applicable Data Protection Laws.
- "Security Incident" means a confirmed breach of security leading to the accidental or unlawful destruction, loss, alteration, or unauthorised disclosure of or access to Customer Data processed by Company or its Subprocessors. Unsuccessful attempts or activities that do not compromise the security of Customer Data, such as failed log-in attempts, pings, port scans and denial-of-service attacks, are not Security Incidents.
- "Service-Generated Data" means usage data, telemetry and metadata generated through the operation and use of the Services, including through support interactions. This Addendum applies to Service-Generated Data only to the extent it contains Personal Data.
- "Subprocessor" means any third party that Company engages to process Customer Data in connection with providing the Services.
3. General; Termination
- This Addendum forms part of the Agreement. Except as expressly set out in this Addendum, the Agreement remains unchanged and in full force and effect. If there is any conflict between this Addendum and the Agreement, this Addendum prevails in relation to the processing of Personal Data.
- Each party's liability arising out of or in connection with this Addendum is subject to the limitations and exclusions of liability in the Agreement.
- This Addendum is governed by the governing law and jurisdiction provisions of the Agreement, unless Applicable Data Protection Laws or Schedule 3 require otherwise.
- This Addendum remains in effect for as long as Company processes Customer Data, and terminates automatically once all Customer Data has been deleted in accordance with Section 12.
- Company may update this Addendum from time to time by publishing a revised version at pdf.co/resources/legal/dpa. Updates will not materially reduce the protections given to Customer Data, except where required to comply with Applicable Data Protection Laws or the guidance of a supervisory authority.
4. Relationship of the Parties
- Company as Processor. For Customer Data, Customer acts as a Controller (or as a Processor on behalf of a third-party Controller), and Company acts as a Processor (or Subprocessor). Company will process Customer Data in accordance with Section 6 and Schedule 1.
- Company as Controller. For Account Data, and for Service-Generated Data to the extent it contains Personal Data, Company acts as an independent Controller and will process that data in accordance with its Privacy Notice and Applicable Data Protection Laws. The Processor obligations in this Addendum do not apply to that data.
5. Compliance with Law
Each party will comply with the obligations that Applicable Data Protection Laws place on it in respect of its processing of Personal Data under the Agreement.
6. Role and Scope of Processing
- Customer responsibilities. Customer is solely responsible for the accuracy, quality and lawfulness of Customer Data and the means by which it was obtained. Customer confirms that it has provided all notices, obtained all consents, and secured all rights necessary under Applicable Data Protection Laws for Company to process Customer Data as contemplated by the Agreement.
- Customer instructions. Company will process Customer Data only on Customer's documented instructions, unless otherwise required by law to which Company is subject, in which case Company will inform Customer of that requirement before processing unless the law prohibits it. By entering into the Agreement, Customer instructs Company to process Customer Data:
- to provide, maintain, secure and support the Services;
- as further directed through Customer's use and configuration of the Services, including any optional features Customer chooses to enable;
- to perform its obligations and exercise its rights under the Agreement; and
- to comply with its legal obligations and to establish, exercise or defend legal claims.
- Unlawful instructions. Company will notify Customer if it believes an instruction infringes Applicable Data Protection Laws, and may suspend the relevant processing until the instruction is confirmed or modified.
- Confidentiality. Company will ensure that everyone it authorises to process Customer Data is bound by an appropriate duty of confidentiality, and that access is limited to those who need it to provide the Services.
7. Subprocessing
- Authorisation. Customer specifically authorises Company to engage its Affiliates as Subprocessors and generally authorises Company to engage other Subprocessors. For each Subprocessor, Company will:
- enter into a written agreement that imposes data protection obligations substantially similar to those in this Addendum, to the extent appropriate to the services provided; and
- remain liable to Customer for any act or omission of the Subprocessor that causes Company to breach this Addendum.
- Subprocessor list. The current list of Subprocessors, including their functions and locations, is available at pdf.co/resources/legal/subprocessors.
- Notice of changes. Company will notify Customer by email, sent to the email address associated with Customer's account, of any intended addition or replacement of a Subprocessor at least thirty (30) days before the new Subprocessor begins processing Customer Data, and will update the Subprocessor list accordingly.
- Objections. Customer may object to a new Subprocessor on reasonable data protection grounds by notifying the PDF.co Support Team within ten (10) days of receiving notice under Section 7.3. If Customer does not object within that period, the new Subprocessor is deemed approved. If Customer objects, the parties will discuss the objection in good faith. If they cannot resolve it before the new Subprocessor begins processing Customer Data, Customer may, as its sole and exclusive remedy, terminate the affected Services by written notice.
8. Security
-
Security measures. Company will implement and maintain appropriate technical and organisational measures designed to protect Customer Data against Security Incidents and to preserve its confidentiality, integrity and availability, as described in Schedule 2 ("Security Measures"). Company may update the Security Measures from time to time, provided the updates do not materially reduce the overall level of protection.
-
Customer responsibilities. Customer is responsible for reviewing the information Company makes available about its security and deciding whether the Services meet Customer's own requirements and legal obligations. Customer is also responsible for its own use of the Services, including:
- configuring and using the Services in a way that provides a level of security appropriate to the risk;
- protecting the credentials, systems and devices it uses to access the Services; and
- keeping its own backups of Customer Data where appropriate.
-
Security Incidents. On becoming aware of a Security Incident, Company will notify Customer without undue delay and in any event within forty-eight (48) hours, unless prohibited by law. A delay requested by law enforcement will not count as undue delay. The notice will describe, to the extent known:
- the nature of the Security Incident, including the categories and approximate volume of Customer Data and Data Subjects affected;
- its likely consequences; and
- the steps Company has taken or proposes to take to contain and mitigate it.
Company will provide further information in phases as it becomes available and will take reasonable steps to contain, investigate and remediate the Security Incident. Customer is responsible for any notifications it is required to make to regulators or Data Subjects. Company's notification of or response to a Security Incident is not an acknowledgement of fault or liability. This Section 8.3 does not apply to Security Incidents caused by Customer or its users.
9. Audits and Reviews of Compliance
- Independent assessment. Company's security controls are assessed by independent auditors against the SOC 2 Type II framework, at Company's expense, on an annual cycle (the resulting report being an "Audit Report").
- Access to information. On Customer's written request, no more than once per year and subject to reasonable confidentiality terms, Company will provide Customer with a copy of its most recent Audit Report (where one is available) and respond to reasonable written security questionnaires.
10. Impact Assessments and Consultations
Where Customer does not otherwise have access to the relevant information, Company will provide reasonable cooperation in connection with any data protection impact assessment or prior consultation with a supervisory authority that Customer is required to carry out under Applicable Data Protection Laws. Company may charge a reasonable fee where this cooperation requires significant resources.
11. Data Subject Requests
- The Services include self-service functionality that allows Customer to access, export and delete Customer Data. Where Customer cannot fulfil a Data Subject request using that functionality, Company will provide reasonable assistance, taking into account the nature of the processing.
- If Company receives a request directly from a Data Subject relating to Customer Data, it will direct the Data Subject to Customer, unless prohibited by law. Customer is responsible for responding to such requests.
12. Return or Deletion of Customer Data
- Customer may export or delete Customer Data at any time during the term of the Agreement using the functionality of the Services.
- Termination or expiry of the Agreement is Customer's instruction to delete Customer Data. Company will delete Customer Data within thirty (30) days of termination or expiry, and from backups within a further ninety (90) days in line with its standard backup rotation. Customer should export any Customer Data it wishes to keep before the Agreement ends.
- Company may retain Customer Data where required by law. Any retained Customer Data remains subject to this Addendum for as long as it is held.
- On request, Company will confirm in writing that deletion has been completed.
13. International Provisions
-
Processing locations. Customer Data is primarily hosted in the US West. Customer acknowledges that Company and its Subprocessors may process Customer Data in other countries where they operate, as described in the Subprocessor list. Company will ensure any such transfers comply with Applicable Data Protection Laws and this Addendum.
-
Transfer mechanisms. Where a transfer of Personal Data from the EEA, the UK or Switzerland to a country without an adequacy decision requires a transfer mechanism, Schedule 3 applies.
-
Jurisdiction-specific terms. Where Company processes Customer Data protected by the laws of a jurisdiction listed in Schedule 4, the terms for that jurisdiction apply in addition to this Addendum.
-
Government access requests. If Company receives a legally binding request from a law enforcement or other public authority for access to Customer Data, Company will:
- attempt to redirect the authority to request the data directly from Customer, and may provide Customer's basic contact information to the authority for that purpose;
- unless legally prohibited, notify Customer promptly so that Customer can seek a protective order or other appropriate remedy, and cooperate reasonably with Customer in doing so;
- review the lawfulness of the request and challenge it where there are reasonable grounds to do so; and
- if compelled to disclose, disclose only the minimum Customer Data necessary to comply.
Company will not voluntarily disclose Customer Data to any law enforcement or other public authority.
Schedule 1: Details of Processing
This Schedule serves as Annex I.B to the Standard Contractual Clauses where applicable.
Part A: Customer Data (Company as Processor)
1. Nature and Purpose of Processing
Company processes Customer Data as necessary to provide, maintain, secure and support the Services, in accordance with the Agreement and Customer's instructions under Section 6. Company does not sell Customer Data and does not share it with third parties for their own purposes.
2. Processing Activities
Collection, storage, hosting, organisation, retrieval, transmission, backup, analysis and deletion of Customer Data as required to provide the Services, and disclosures required by law.
3. Duration of Processing
For the term of the Agreement, and afterwards until deletion in accordance with Section 12.
4. Categories of Data Subjects
Individuals whose Personal Data is included in Customer Data. Depending on how Customer uses the Services, this may include Customer's employees, contractors and other authorised users; Customer's own customers, prospects and end users; and Customer's business contacts and suppliers.
5. Categories of Personal Data
Any Personal Data that Customer or its users submit to the Services, the extent of which is determined and controlled solely by Customer. This typically includes names, email addresses, phone numbers, job titles, and any other Personal Data contained in documents and other content submitted to the Services.
6. Sensitive Data
Company does not intend to process special categories of Personal Data or Personal Data relating to criminal convictions and offences. Any such data is processed only if Customer chooses to include it in content submitted to the Services, in which case it is protected by the Security Measures in Schedule 2. Customer is responsible for ensuring that it has a lawful basis for submitting any such data.
7. Frequency of Transfer
Continuous, for the duration of the Agreement.
8. Transfers to Subprocessors
The subject matter, nature and duration of processing by each Subprocessor is described in the Subprocessor list referred to in Section 7.2.
Part B: Account Data (Company as Controller)
1. Nature and Purpose of Processing
Company processes Account Data to create and administer Customer's account, provide customer support, process billing and payments, communicate with Customer about the Services, and comply with its legal obligations.
2. Categories of Data Subjects
Customer's authorised users, account administrators, and billing and technical contacts.
3. Categories of Personal Data
Names, email addresses, job titles, company names, billing details, and the content of support communications.
4. Sensitive Data
None.
5. Frequency of Transfer
Continuous, for the duration of the Agreement.
6. Retention
As described in Company's Privacy Notice.
Schedule 2: Technical and Organisational Security Measures
This Schedule serves as Annex II to the Standard Contractual Clauses where applicable.
| Technical and Organisational Security Measure | Details |
|---|---|
| Measures for encryption of Personal Data | Customer Data is encrypted in transit using TLS 1.2 or higher and at rest using AES-256. |
| Measures for ensuring ongoing confidentiality, integrity, availability and resilience of processing systems and services | All personnel are bound by confidentiality obligations. The Services are hosted in AWS data centres, and Company's controls are assessed annually against the SOC 2 Type II Security and Processing Integrity Trust Services Criteria. |
| Measures for ensuring the ability to restore the availability of and access to Personal Data in a timely manner in the event of a physical or technical incident | Daily backups of production datastores are taken. Backups are tested periodically in accordance with Company's information security and data management policies. |
| Processes for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures in order to ensure the security of the processing | Company's controls are assessed annually by independent auditors against the SOC 2 Type II Security and Processing Integrity Trust Services Criteria. |
| Measures for user identification and authorisation | Company uses secure access protocols and follows industry best practice for authentication, including multi-factor authentication and single sign-on (SSO). All production access requires multi-factor authentication. Network infrastructure is configured to vendor and industry best practice to block unnecessary ports, services and unauthorised network traffic. |
| Measures for the protection of data during transmission | Company uses only recommended secure cipher suites and protocols to encrypt all traffic in transit, using TLS 1.2 or higher. |
| Measures for the protection of data during storage | Encryption at rest is automated using AWS transparent disk encryption, which uses AES-256 to secure all volume (disk) data. Keys are managed by AWS. |
| Measures for ensuring physical security of locations at which Personal Data are processed | All Company processing takes place in physical data centres managed by AWS. See AWS data centre controls. |
| Measures for ensuring events logging | Company monitors access to applications, tools and resources that process or store Customer Data, including cloud services. |
| Measures for ensuring system configuration, including default configuration | Company follows a change management process for all changes to the production environment, including its underlying software, applications and systems. All production changes are deployed through automated CI/CD tooling to ensure consistent configuration. |
| Measures for internal IT and IT security governance and management | Company's security programme includes administrative, organisational, technical and physical safeguards reasonably designed to protect the Services and the confidentiality, integrity and availability of Customer Data. |
| Measures for certification and assurance of processes and products | Company's controls are assessed annually by independent auditors against the SOC 2 Type II framework. |
| Measures for ensuring data minimisation | Customers determine what data they submit to the Services, under a shared responsibility model. Company gives Customers control over what data enters the Services and provides self-service functionality to delete data at their discretion. |
| Measures for ensuring data quality | Company maintains the integrity of Customer Data from the time it is submitted to the Services until it is returned or exported. |
| Measures for ensuring limited data retention | Customers determine what data they submit to the Services, under a shared responsibility model. If Customer cannot delete Personal Data using the self-service functionality, Company will delete it on Customer's written request within the timeframes in Section 12 of this Addendum. All Customer Data is deleted following termination in accordance with Section 12. |
| Measures for ensuring accountability | Company has adopted data protection and information security policies across the business, records and reports Security Incidents, formally assigns roles and responsibilities for information security and data privacy, and undergoes regular independent audits. |
| Measures for allowing data portability and ensuring erasure | Customer Data may be deleted by Customer or at Customer's request. Following privacy by design and data minimisation principles, Personal Data is incidental to the Services and Company limits its collection and processing. Company will respond to any data portability requests to address Customer's needs. |
| Technical and organisational measures of Subprocessors | Company enters into written agreements with its Subprocessors that impose data protection obligations substantially similar to those in this Addendum, including obligations to notify Company of security incidents, delete data when instructed, and not engage further subprocessors without authorisation. |
Schedule 3: Cross-Border Transfer Mechanisms
1. Definitions
- "Standard Contractual Clauses" or "SCCs" means the standard contractual clauses approved by the European Commission in Implementing Decision (EU) 2021/914.
- "UK Addendum" means the International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner, as completed in Schedule 5.
- "Data Exporter" means Customer, and "Data Importer" means Company.
- "Restricted Transfer" means a transfer of Personal Data from the EEA, the UK or Switzerland to a country that is not recognised under Applicable Data Protection Laws as providing an adequate level of protection.
2. Order of Precedence of Transfer Mechanisms
Where more than one transfer mechanism could apply to a transfer, the parties will rely on them in the following order: (a) an adequacy decision covering the destination country; (b) where Company or the relevant Subprocessor is certified, the EU-U.S. Data Privacy Framework, its UK Extension, or the Swiss-U.S. Data Privacy Framework; and (c) the SCCs, together with the UK Addendum or the Swiss amendments in Section 6 of this Schedule where applicable.
3. Transfers to the United States
Customer acknowledges that Company's primary processing operations take place in the United States, and that transferring Personal Data to the United States is necessary to provide the Services. Company may transfer Personal Data outside the EEA, the UK or Switzerland as necessary to provide the Services, and will ensure that each Restricted Transfer is protected by an appropriate safeguard in accordance with Applicable Data Protection Laws and this Schedule.
4. EU Transfers: Standard Contractual Clauses
For Restricted Transfers from the EEA, the SCCs are deemed entered into and incorporated into this Addendum by reference, and are completed as follows:
- Modules.
- Module One (Controller to Controller) applies where Customer transfers Account Data to Company and Company processes it as a Controller.
- Module Two (Controller to Processor) applies where Customer is a Controller and Company processes Customer Data as a Processor.
- Module Three (Processor to Processor) applies where Customer is a Processor and Company processes Customer Data as a Subprocessor.
- Clause 7 (docking clause): does not apply.
- Clause 9(a) (Modules Two and Three): Option 2 (general written authorisation) applies, and the notice period for changes to Subprocessors is thirty (30) days, as set out in Section 7.3 of this Addendum.
- Clause 11(a): the optional language does not apply.
- Clause 13: the competent supervisory authority is determined in accordance with Clause 13(a).
- Clause 17: Option 1 applies, and the SCCs are governed by the law of Ireland.
- Clause 18(b): disputes are resolved before the courts of Ireland.
- Annex I.A (List of Parties):
- Data Exporter: Customer, as identified in the Agreement. Contact details: the email address associated with Customer's account. Activities relevant to the transfer: use of the Services. Role: Controller or Processor, as described in Section 4 of this Addendum.
- Data Importer: Artifex Software, Inc. Contact details: Artifex Compliance Manager, via the PDF.co Support Team. Activities relevant to the transfer: provision of the Services. Role: Processor (Modules Two and Three) or Controller (Module One), as described in Section 4 of this Addendum.
- Signature and date: by entering into the Agreement, each party is deemed to have signed the SCCs, including their Annexes, as of the Effective Date.
- Annex I.B (Description of Transfer): Schedule 1 (Part A for Modules Two and Three; Part B for Module One).
- Annex I.C (Competent Supervisory Authority): as determined in accordance with Clause 13 of the SCCs.
- Annex II (Technical and Organisational Measures): Schedule 2.
- Annex III (List of Subprocessors): the Subprocessor list referred to in Section 7.2 of this Addendum.
References in this Section to "Clauses" and "Annexes" are to the clauses and annexes of the SCCs.
5. UK Transfers
For Restricted Transfers from the UK, the SCCs as completed in Section 4 of this Schedule apply, as amended by the UK Addendum in Schedule 5.
6. Swiss Transfers
For Restricted Transfers from Switzerland, the SCCs as completed in Section 4 of this Schedule apply with the following amendments:
- references to the GDPR are to be read as references to the FADP, to the extent the transfer is subject to the FADP;
- the Swiss Federal Data Protection and Information Commissioner is the competent supervisory authority for transfers subject to the FADP, and the supervisory authority determined under Section 4 of this Schedule remains competent for transfers subject to the GDPR; and
- the term "Member State" is not to be interpreted in a way that prevents Data Subjects in Switzerland from bringing claims in their place of habitual residence, in accordance with Clause 18(c) of the SCCs.
7. Supplementary Measures
For Restricted Transfers from the EEA, the UK or Switzerland, the following supplementary measures apply in addition to the SCCs:
- As of the date of this Addendum, Company has not received any legally binding request from a government intelligence, security or law enforcement authority for access to Customer Data.
- Company will handle any such request in accordance with Section 13.4 of this Addendum. If Company receives such a request, the parties will discuss, as soon as reasonably practicable, whether any transfers under this Addendum should be suspended.
- The parties will consult as needed to consider whether the laws of the Data Importer's country provide protection broadly equivalent to that of the EEA, the UK or Switzerland (as applicable); whether additional measures are reasonably necessary to keep the transfer compliant; and whether it remains appropriate to continue the transfer, taking into account the guidance of the supervisory authorities.
- If Applicable Data Protection Laws require the SCCs to be executed as a separate agreement for a particular transfer, Company will, at Customer's request, promptly execute them with the amendments reasonably required to reflect the relevant annexes, the details of the transfer and the requirements of Applicable Data Protection Laws.
8. Alternative Mechanisms
If a transfer mechanism relied on under this Schedule ceases to be valid, or a supervisory authority requires transfers under it to be suspended, Company may, by notice to Customer, put in place an alternative lawful transfer mechanism, and the parties will cooperate in good faith to implement it without undue delay.
9. Conflicts
If there is any conflict between the SCCs or the UK Addendum and any other term of this Addendum, including Schedule 4, the SCCs or the UK Addendum (as applicable) prevail.
Schedule 4: Jurisdiction-Specific Terms
1. California
- Terms such as "business", "service provider", "sell", "share", "business purpose", "commercial purpose" and "personal information" have the meanings given in the CCPA.
- For Customer Data, Company acts as Customer's service provider. Company will not:
- sell or share Customer Data;
- retain, use or disclose Customer Data for any purpose other than the business purposes specified in the Agreement, including for any commercial purpose other than providing the Services;
- retain, use or disclose Customer Data outside the direct business relationship between the parties; or
- combine Customer Data with personal information it receives from other sources, except as permitted by the CCPA.
- Company will provide the same level of privacy protection as the CCPA requires of businesses, and will notify Customer if it determines it can no longer meet its obligations under the CCPA. Customer may, on reasonable notice, take reasonable and appropriate steps to stop and remediate any unauthorised use of Customer Data.
- The parties agree that Company's access to Customer Data is not part of the consideration exchanged under the Agreement.
- Company certifies that it understands and will comply with the restrictions in this Section 1.
2. European Economic Area
When engaging a Subprocessor, Company will impose the obligations required by Article 28(3) of the GDPR, including sufficient guarantees that appropriate technical and organisational measures will be implemented.
3. Switzerland
References to the GDPR in this Addendum are to be read, where applicable, as references to the corresponding provisions of the FADP, and Section 2 of this Schedule applies accordingly.
4. United Kingdom
References to the GDPR in this Addendum are to be read, where applicable, as references to the corresponding provisions of the UK GDPR and Data Protection Act 2018, and Section 2 of this Schedule applies accordingly.
Schedule 5: UK International Data Transfer Addendum
This Schedule completes the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses (version B1.0) issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018 (the "Approved Addendum"). The Mandatory Clauses in Part 2 of the Approved Addendum, as revised from time to time, are incorporated into this Addendum by reference.
Part 1: Tables
Table 1: Parties
| Exporter | Importer | |
|---|---|---|
| Start date | The Effective Date | The Effective Date |
| Parties' details | Customer, as identified in the Agreement | Company, as identified in the Agreement |
| Key contact | As identified in the Agreement or Customer's account | Artifex Compliance Manager, via the PDF.co Support Team |
| Signature | Deemed signed by entering into the Agreement | Deemed signed by entering into the Agreement |
Table 2: Selected SCCs, Modules and Clauses
The Approved EU SCCs, including the Appendix Information, with only the modules, clauses and optional provisions selected in Schedule 3, Section 4 brought into effect for the purposes of this UK Addendum.
Table 3: Appendix Information
| Annex | Location |
|---|---|
| Annex 1A: List of Parties | Table 1 above and Schedule 3, Section 4.8 |
| Annex 1B: Description of Transfer | Schedule 1 |
| Annex II: Technical and Organisational Measures | Schedule 2 |
| Annex III: List of Subprocessors | The Subprocessor list referred to in Section 7.2 |
Table 4: Ending the UK Addendum When the Approved Addendum Changes
| Details | Parties |
|---|---|
| Which parties may end this UK Addendum as set out in Section 19 of the Mandatory Clauses | Both Importer and Exporter |
Part 2: Mandatory Clauses
The Mandatory Clauses are Part 2 of the Approved Addendum: template Addendum B1.0, issued by the ICO and laid before Parliament under section 119A of the Data Protection Act 2018 on 2 February 2022, as revised under Section 18 of those Mandatory Clauses. They are incorporated into this Addendum by reference and apply exactly as the ICO published them. The parties may not change them, except where the Mandatory Clauses themselves allow it. The official text is available on the ICO website at https://ico.org.uk/media2/migrated/4019539/international-data-transfer-addendum.pdf.