The Skillable logo on a white background

Skillable - DATA PROCESSING ADDENDUM

 

Updated and Effective: March 2026

This Data Processing Addendum (including all its Exhibits and Annexes, collectively, “Addendum”) supplements, as applicable, the Master Services Agreement, Reseller Master Agreement, Order, Statement of Work or other services agreement that refers to or incorporates this Addendum (“Principal Agreement”) is between Hands-on Learning Solutions LLC d.b.a. Skillable (“Service Provider”) and the customer, reseller, or company identified in the Principal Agreement (“Customer”). Service Provider and Customer are referred to individually as a “Party” and collectively as the “Parties.”

Get policy change updates in your inbox

To receive notifications of changes to our privacy and/or data policies, click here.

RECITALS

WHEREAS, in the course of performing the services under the Principal Agreement, Service Provider may process Customer Personal Data (as defined herein); and

WHEREAS, the Parties wish the processing by Service Provider of such Customer Personal Data also to be governed by the provisions of this Addendum.

NOW, THEREFORE, in consideration of the mutual obligations set out herein and in the Principal Agreement, the Parties hereby agree that this Addendum shall be added to the Principal Agreement.

1. Definitions

The following list of terms and definitions are applicable to this Addendum.

a. “Applicable Laws” means (a) international, national, federal, or state laws and regulations of any kind; and (b) Data Protection Laws, in each case that are applicable to the activities of the Parties, and as they may be amended, supplemented, or substituted from time to time.

b. “Authorized Persons” means any person who Processes Customer Personal Data on Service Provider’s behalf, including Service Provider’s employees, officers, partners, principles, contractors and Subprocessors.

c. “CCPA” means the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act, set forth in Cal. Civ. Code 1798.100, et. seq., and their implementing regulations.

d. “Customer Personal Data” means Personal Data that is Processed by Service Provider in connection with the provision of the Services that is controlled by Customer or, where Customer acts as a Processor, by the applicable Controller(s).

e. “Data Protection Laws” means the European Data Protection Laws and, to the extent applicable to the activities of the Parties referred to in this Addendum, the data protection or privacy laws of the United States (and individual US States, including without limitation the CCPA), and of any other territory.

f. “EEA” means the European Economic Area.

g. “European Data Protection Laws” means the GDPR, Directive 2002/58/EC concerning the processing of personal data and the protection of privacy in the electronic communications sector, and all EEA member state implementations of any of them, as well as Data Protection Laws in effect in the United Kingdom and Switzerland.

h. “GDPR” means the EU General Data Protection Regulation 2016/679 of the European Parliament and of Council.

i. “Model Clauses” means:

(x) in respect of Customer Personal Data transferred from the EEA or Switzerland: the unchanged version of the applicable module(s) of the standard contractual clauses in Commission Decision 2021/914/EU which can be found at https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32021D0914&from=EN) (also referred to as the “EU SCCs”), as further provided in Exhibit C to this Addendum; and

(y) in respect of Customer Personal Data transferred from the United Kingdom: the applicable adaptations to the EU SCCs (the “UK Addendum”) as referred to in Annex IV of Exhibit C to this Addendum.

j. “Services” means the services and other activities to be supplied to or carried out by or on behalf of Service Provider for Customer in accordance with the Principal Agreement.

k. “Subprocessor” means any third party engaged by Service Provider to Process Customer Personal Data.

l. The terms “Controller”, “Data Subject”, “Member State”, “Personal Data”, “Personal Data Breach”, “Process”, “Processor”, and “Supervisory Authority” shall have the same meaning as set forth in Data Protection Laws.

m. Capitalized terms not otherwise defined in this Addendum shall have the meaning given to them in the Principal Agreement.

2. Processing of Customer Personal Data

a. The Parties hereby acknowledge and agree in relation to Customer Personal Data that:

i. Customer is acting as a Controller and Service Provider as a Processor; and/or

ii. where Customer is permitted to provide or resell the Services to third parties (e.g., clients or affiliates of Customer) who act as Controllers, then Customer is acting as a Processor, and Service Provider is acting as a sub-Processor.

b. Where Customer is a Processor of Customer Personal Data then:

i. Customer, acting as authorized by the applicable Controller(s), hereby appoints Service Provider as a sub-Processor in respect of all Processing operations required to be carried out by Service Provider on Customer Personal Data in order to provide the Services; and

ii. Customer represents and warrants that Customer has been instructed by and obtained the authorization of each relevant Controller to engage Service Provider as a sub-Processor of Customer Personal Data.

c. Service Provider shall in Processing Customer Personal Data:

i. comply with all applicable Data Protection Laws; and

ii. not engage in any Processing of Customer Personal Data other than in accordance with Customer’s documented instructions including as set forth in Exhibit A to this Addendum, unless that other Processing is required by Applicable Laws (in which case Service Provider shall inform Customer of such requirement).

d. Customer:

i. instructs and authorizes Service Provider and each Subprocessor to: (1) Process Customer Personal Data; and (2) if applicable, transfer Customer Personal Data to any country or territory in compliance with Section 10 of this Addendum and applicable Data Protection Laws; in each case as reasonably necessary for the provision of the Services;

ii. warrants and represents to Service Provider that it is and will, at all relevant times: (1) comply with applicable Data Protection Laws, (2) have in place all necessary authorizations and approvals to enter, use, provide, store, and Process Customer Personal Data to enable Service Provider to provide the Services; and (3) remain duly and effectively authorized to give the instructions referred to in this Addendum.

e. Service Provider shall immediately inform Customer if, in Service Provider’s opinion, any instruction from Customer infringes Applicable Laws.

f. Exhibit A to this Addendum sets out further details regarding the Service Provider’s Processing of Customer Personal Data. By agreement in writing (including by email) the Parties may make reasonable amendments to Exhibit A as reasonably necessary to meet the requirements of the Services or Data Protection Laws.

g. To the extent that Customer Personal Data constitutes personal information of California Consumers that is subject to the CCPA, then the provisions of Exhibit B shall also apply to the Processing of such Customer Personal Data.

3. Service Provider Personnel

Service Provider shall:

a. take reasonable steps to ensure the reliability of any Authorized Persons who may have access to the Customer Personal Data, ensuring in each case that access is strictly limited to those individuals who need to know and have access to the relevant Customer Personal Data, as required for carrying out Service Provider’s obligations under the Principal Agreement and to comply with Applicable Laws; and

b. ensure that all Authorized Persons that Process Personal Data are bound by an appropriate contractual or statutory duty of confidentiality.

4. Subprocessing

a. Customer authorizes Service Provider to appoint Subprocessors as set forth in this Section 4 and in accordance with the Principal Agreement.

b. Service Provider may continue to use those Subprocessors that are already engaged by Service Provider as of the Effective Date of the Principal Agreement, provided that Service Provider ensures that each Subprocessor meets the obligations set forth in Section 4(e) below. A current list of Subprocessors is set forth in Skillable’s Trust Center here: https://www.skillable.com/company/legal-and-security/subprocessors/.

c. Customer agrees to receive updates to Skillable’s Subprocessor list by subscribing to updates from Skillable’s Trust Center here: https://www.skillable.com/company/legal-and-security/subprocessors/. Skillable may also provide notice of changes by email.

d. If Customer provides notice to Service Provider of any reasonable objections to a proposed Subprocessor, in writing, within ten (10) days of Service Provider informing Customer of the proposed appointment of such Subprocessor, then the Parties shall seek a reasonable approach to Processing of Customer Personal Data that overcomes Customer’s objections, failing which Service Provider shall either:

i. not engage the Subprocessor to Process Customer Personal Data; or

ii. permit Customer to suspend or terminate the Processing of Personal Data under the Principal Agreement and/or immediately suspend or terminate the Principal Agreement, in each case without penalty.

e. Service Provider shall:

i. engage Subprocessors in accordance with Data Protection Laws;

ii. conduct adequate due diligence on the Subprocessor, prior to such Subprocessor engaging in any Processing of Customer Personal Data, to ensure that the Subprocessor has the capability to provide an adequate level of protection for Customer Personal Data in accordance with this Addendum and Data Protection Laws;

iii. ensure the Service Provider has a contractual arrangement with the Subprocessor, which imposes equivalent data protection terms and conditions on such Subprocessor as are set forth in this Addendum, and complies with the requirements of applicable Data Protection Laws;

iv. remain fully liable for any breach of this Addendum or the Principal Agreement that is caused by an act, error or omission of Service Provider’s Subprocessor; and

v. where required, enter into an agreement incorporating the applicable Model Clauses (and any other provisions required by Data Protection Laws) with the Subprocessor.

5. Cooperation

a. Service Provider shall reasonably cooperate with Customer, including by appropriate technical and organizational measures, to enable Customer (and/or the applicable Controller(s)) to respond to any requests, complaints or other communications from a Data Subject, and governmental, regulatory or judicial bodies relating to the Processing of Customer Personal Data, including requests from data subjects seeking to exercise their rights under Data Protection Laws. If any such request, complaint or communication is received by or otherwise made directly to Service Provider, Service Provider shall, to the extent not prohibited by Applicable Laws, immediately notify Customer and will not respond to such communication without Customer’s express authorization.

b. Except as otherwise prohibited by Applicable Laws, if Service Provider receives a subpoena, court order, warrant or other legal demand from a third party, including, but not limited to law enforcement or other governmental, regulatory or judicial authorities, seeking the disclosure of Customer Personal Data, Service Provider shall not disclose any Customer Personal Data without first immediately notifying Customer, in writing, of such request in order to allow Customer at Customer’s sole expense to limit, challenge, or protect against such disclosure.

c. Service Provider and each Subprocessor shall provide reasonable assistance to Customer (and/or the applicable Controller(s)) with any data protection impact assessments, and consultations with Supervisory Authorities or other competent data protection authorities, as may be required of Customer under Data Protection Laws, in relation to the Processing of Customer Personal Data.

6. Personal Data Breach

a. In the event of a Personal Data Breach affecting Customer Personal Data, Service Provider shall:

i. inform Customer of the Personal Data Breach without undue delay and in no event later than forty-eight (48) hours after Service Provider first becomes aware of the occurrence of such Personal Data Breach; and

ii. as soon as practicable provide Customer with sufficient information in order to allow Customer to meet any obligations it may have to report or inform Supervisory Authorities and/or Data Subjects of the Personal Data Breach under Data Protection Laws, including when known all information required to be provided by Data Protection Laws.

b. Service Provider shall take such measures and actions as appropriate to remedy or mitigate the effects of the Personal Data Breach and shall cooperate with Customer by providing regular updates and other reasonably requested information about developments in connection with the Personal Data Breach response, investigation and remediation activities.

c. Any press release or public announcement or public communication concerning a Personal Data Breach shall be made solely at Customer’s discretion, except as otherwise required by Applicable Laws.

7. Security

a. As concerns the Processing of Customer Personal Data pursuant to the Principal Agreement and this Addendum, Service Provider shall take into account the state of the art, costs of implementation and the nature, scope, context and purposes of Processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons (“Assessment of the Risks”).

b. Service Provider and each relevant Subprocessor, in relation to Processing the Customer Personal Data under the Principal Agreement or this Addendum, shall implement the appropriate technical and organizational measures to ensure a level of security appropriate to the Assessment of Risks, including the measures set out in Annex II of Exhibit B to this Addendum and any measures required by Data Protection Laws.

8. Audit Reports and Inspection

a. Service Provider shall keep records of Service Provider’s Processing activities in accordance with Data Protection Laws.

b. Upon reasonable written request by Customer, Service Provider shall provide copies of reasonable information necessary to demonstrate Service Provider’s compliance with this Addendum.

c. If such information is not sufficient to enable Customer reasonably to judge Service Provider’s compliance with this Addendum, Customer will provide a writing detailing its concerns. The parties will meet via a video call between senior personnel to discuss Customer’s concerns, and if the parties do not reach resolution within 30 days of such meeting, or if an audit is required by Data Protection Laws, Service Provider shall allow for and provide reasonable cooperation with an audit under this Addendum at Customer’s sole expense, including inspections by any Customer or Customer’s auditor (that is bound by reasonable non-disclosure obligations covering Service Provider’s non-public information), in relation to the Processing of Customer Personal Data.

d. Customer shall give Service Provider reasonable written notice of any audit or inspection and shall make reasonable efforts to avoid causing disruption to the Service Provider’s premises, equipment, personnel and business while Customer or auditor personnel are on the premises conducing an audit or inspection.

e. No audit or inspection may take place outside of normal business hours for the premises where the audit or inspection will be conducted.

f. No more than one audit or inspection shall be permissible in any calendar year, with respect to the Service Provider, except where:

i. such audit or inspection is carried out in response to a Personal Data Breach affecting Customer Personal Data; or

ii. Customer is required or requested to carry out an audit or inspection by Data Protection Laws, a Supervisory Authority or any similar regulatory authority responsible for the enforcement of Data Protection Laws in any country or territory, or

iii. Where Customer has completed an audit or inspection of Service Provider and identified concerns or requirements that need addressed in its notice to Service Provider or a relevant Subprocessor and wishes to follow-up to ensure such concern or requirement has been adequately addressed where Service Provider or the applicable Subprocessor does not otherwise demonstrate adequate compliance or corrections.

9. Deletion & Return of Customer Personal Data

a. Upon Customer’s (or as applicable the relevant Controller’s) request, Service Provider shall promptly destroy or return to Customer (or as applicable the relevant Controller) all Customer Personal Data in its possession or control, including any Customer Personal Data Processed by Subprocessors.

b. Such requirement shall not apply to the extent that Service Provider is required by Applicable Laws to retain some or all of the Customer Personal Data, in which case, Service Provider shall Process such Customer Personal Data only for that purpose.

10. Transfers of Customer Personal Data

a. The Parties acknowledge that the provision of the Services may entail a transfer to Service Provider of Customer Personal Data outside of the territory in which the Personal Data was first collected.

b. Any such transfer of Customer Personal Data shall take place only:

i. in compliance with Applicable Laws; and

ii. where such Customer Personal Data is transferred from the EEA or the UK to a place that is not designated as an “adequate” territory by the applicable EU or UK authorities, in accordance with the Model Clauses.

c. to the extent that Processing of Customer Personal Data by a Subprocessor entails a transfer of Personal Data from the EEA or UK to a non-adequate territory, Service Provider shall also ensure that such Subprocessor agrees to comply with the Model Clauses.

11. General Terms

a. Except as set forth in this Addendum, the Principal Agreement shall remain unchanged and in full force and effect.

b. In the event of any conflict between the provision of this Addendum and any provision in the Principal Agreement, this Addendum shall control and take precedence. If there is a conflict or inconsistency between this Addendum and the Model Clauses, the Model Clauses shall prevail and take precedence.

c. The obligations imposed upon Service Provider under this Addendum shall survive the expiration or termination of this Addendum for so long as Service Provider Processes Customer Personal Data.

d. Without prejudice to the provisions of the Model Clauses, in relation to any disputes or claims arising under this Addendum, including disputes regarding its existence, validity or termination or the consequences of its nullity, this Addendum shall be governed by the laws applicable to the Principal Agreement and the parties hereby agree and consent to the jurisdiction set forth in the Principal Agreement.

e. In the event any provision of this Addendum is declared to be invalid or unenforceable, then the remainder of this Addendum shall remain valid and in full force and effect. The invalid or unenforceable provision shall be amended as necessary to ensure its validity and enforcement, which preserving the Parties’ intentions or, if this is not possible, construed in a manner as if the invalid or unenforceable part had never been contained therein.

f. This Addendum may not be modified except by a written instrument signed by both Parties. In the event of changes to Applicable Laws or the Model Clauses, the Parties shall agree in writing any reasonable and necessary adjustments to this Addendum.

EXHIBIT A: CALIFORNIA DATA PROCESSING

a. In this Exhibit, the expressions “business”, “business purpose”, “commercial purpose”, “consumer”, “personal information”, “sell”, “share”, and “service provider” shall have the same definitions as in the CCPA, and “California Personal Information” refers to Customer Personal Data relating to a California consumer.

b. Without limiting the generality of the Parties’ obligations under this Addendum:

i. to the extent Customer provides California Personal Information to Service Provider, then in relation to such California Personal Information:

(1) Customer is a business (or a service provider as applicable), and Service Provider is a service provider;

(2) Customer discloses such California Personal Information to Service Provider for the business purposes set out in the Principal Agreement and this Addendum, and Service Provider will process such California Personal Information solely on Customer’s behalf and only as necessary to perform such business purposes for Customer (or the applicable business);

(3) Service Provider will not:

(a) sell or share such California Personal Information; or

(b) retain, use, or disclose such California Personal Information for any purpose (including a commercial purpose) other than for the specific business purposes of performing the Services specified in the Principal Agreement; or

(c) retain, use, or disclose such California Personal Information outside of the direct business relationship between Customer (and/or the applicable business) and Service Provider; or

(d) combine such California Personal Information with Personal Data that Service Provider receives from, or on behalf of, another person or persons, or collects from Service Provider’s own interaction with individuals (save as specified under Data Protection Laws).

(4) Customer may monitor Service Provider’s compliance with this Addendum, as set out in Section 8 of this Addendum, and as otherwise agreed in writing;

(5) if Service Provider engages any other person to assist Service Provider in processing California Personal Information, such engagement shall be pursuant to a written contract binding such other person to observe all the requirements of this Exhibit, and Service Provider shall notify Customer of that engagement in accordance with the provisions of Section 4 of this Addendum;

(6) Service Provider acknowledges that such California Personal Information is provided to it only for limited and specified purposes as referred to in the Principal Agreement;

(7) Service Provider will comply with its obligations, and provide the same level of privacy protection as is required, under the CCPA;

(8) Service Provider grants to Customer the rights:

(a) to take reasonable and appropriate steps to help to ensure that Service Provider uses such California Personal Information in a manner consistent with Customer’s (and the applicable business(es)’ obligations under the CCPA; and

(b) upon notice, to take reasonable and appropriate steps to stop and remediate any unauthorized use of such California Personal Information; and

(9) Service Provider shall notify Customer promptly if Service Provider makes a determination that Service Provider can no longer meet its obligations under the CCPA.

EXHIBIT B: DETAILS OF PROCESSING OF CUSTOMER PERSONAL DATA BY SERVICE PROVIDER

Subject Matter and Duration of the Processing

Provision of the Services as set forth in the Principal Agreement and this Addendum.

The Nature and Purposes of the Processing Services

Service Provider will host and store Customer Personal Data that is collected and inputted by or on behalf of Customer or the applicable Controller into Service Provider’s learning services system, which Service Provider will Process only in accordance with the Principal Agreement and this Addendum.

Types of Customer Personal Data

Contact information, including first and last name, email address, internet protocol address, and user ID.

Training session information, including the time and duration, responses. and scores or evaluations.

Types of Sensitive Personal Data or Special Categories of Personal Data

None.

Categories of Data Subject to whom the Customer Personal Data relates

Customer’s employees, end-users, and contractors or, where Customer acts as a Processor, those of the applicable Controller(s).

The frequency of the transfer of Customer Personal Data to Service Provider

On a continuous basis.

The period for which the personal data will be retained, or, if that is not possible, the criteria used to determine that period

For so long as the Services are being provided under the Principal Agreement.

For transfers to (sub-) processors, also specify subject matter, nature and duration of the processing

Subprocessors provide services including data storage and web hosting, software, and other ancillary services pursuant to contracts between Service Provider and such Subprocessors (please see Exhibit C, Annex III).

EXHIBIT C: MODEL CLAUSES

1. The Parties agree that transfers from the EEA, Switzerland, and/or the United Kingdom of Customer Personal Information by Customer (as data exporter) to Service Provider (as data importer) as described in Exhibit A shall be governed by the following additional safeguards:

Agreement type: Status of the Parties: Safeguards:
Customer uses the Services within its own businessCustomer is a Controller, and Service Provider is a ProcessorModule TWO of the EU SCCs plus if applicable the UK Addendum
Customer is permitted to provide or resell the Services to third parties who act as ControllersCustomer is a Processor, and Service Provider is a sub-ProcessorModule THREE of the EU SCCs plus if applicable the UK Addendum

 

2. This Exhibit provides the information required by Annexes I, II and III of the EU SCCs and the UK Addendum.

ANNEX I

A. LIST OF PARTIES

Data exporter(s):

1. Name and Address: Customer as identified in the Principal Agreement

Activities relevant to the data transferred under these Clauses:  The data exporter shares the Customer Personal Information with the data importer for the purposes of accessing and receiving the Services as provided under the Principal Agreement.

Signature and date: Signed and dated via the Principal Agreement to which this Addendum is incorporated or attached; no additional signature is required.

Role (controller/processor): Controller or, where Customer Personal Data is controlled by any third party, Processor on behalf of such Controller(s).

Data importer(s):

1. Name: Hands-On Learning Solutions LLC d.b.a. Skillable

Address: 7143 State Road 54, #153, New Port Richey, FL 34653, USA

Contact person’s name, position and contact details: Chief Privacy Officer; privacy@skilllable.com

Activities relevant to the data transferred under these Clauses: Providing the agreed Services and systems, to which the Customer or the applicable Controller may provide certain Customer Personal Data.

Signature and date:  Signed and dated via the Principal Agreement to which this Addendum is incorporated or attached; no additional signature is required.

Role (controller/processor): Processor or, where Customer Personal Data is Processed by Customer as a Processor, Sub-Processor.

B. DESCRIPTION OF TRANSFER

Please see Exhibit A.

C. OPTIONAL PROVISIONS

Clause 7 (Docking Clause), and Clause 9(a) Option 2 (General Authorization with at least 15 days’ notice of changes), shall apply; but not the option under Clause 11 (independent dispute resolution).

D. COMPETENT SUPERVISORY AUTHORITY

The competent supervisory authority as determined in accordance with the Model Clauses, or otherwise The Data Protection Commission in Ireland.

E. GOVERNING LAW AND COMPETENT COURTS

(1) For the purposes of clause 17 of the EU SCCs:
These Clauses shall be governed by the law of the EU Member State in which the data exporter is established, or otherwise the laws of Ireland.

(2) For the purposes of clause 18 of the EU SCCs:
Any dispute arising from these Clauses shall be resolved by the courts of the EU Member State in which the data exporter is established, or otherwise the courts of Ireland.

ANNEX II

TECHNICAL AND ORGANISATIONAL MEASURES INCLUDING TECHNICAL AND ORGANISATIONAL MEASURES TO ENSURE THE SECURITY OF THE DATA

Service Provider shall implement the following technical and organizational measures:
(a) ensure that Customer Personal Data can be accessed only by authorized personnel, on a need to know only basis, for the purposes set forth in Annex I of this Addendum.
(b) take all reasonable measures to prevent unauthorized access to Customer Personal Data through the use of appropriate physical and logical (passwords) entry controls, securing areas for data Processing, and implementing procedures for monitoring the use of data Processing facilities.
(c) establish system and audit trails;
(d) use secure passwords, network intrusion detection technology, encryption and authentication technology, secure logon procedures;
(e) maintain controls to ensure protection against malicious software;
(f) account for all the risks that are presented by Processing, for example from accidental or unlawful destruction, loss, or alteration, unauthorized or unlawful storage, Processing, access or disclosure of Personal Data;
(g) ensure pseudonymisation and/or encryption of Customer Personal Data, where appropriate, including when in transit, at rest and in backups;
(h) maintain the ability to ensure the ongoing confidentiality, integrity, availability and resilience of Processing systems and services;
(i) maintain the ability to restore the availability and access to Customer Personal Data in a timely manner in the event of a physical or technical incident;
(j) implement a process for regularly testing, assessing, and evaluating the effectiveness of technical and organizational measures for ensuring the security of Customer Personal Data;
(k) monitor compliance with the terms of this Addendum and the obligations under the GDPR on an ongoing basis;
(l) implement measures to identify vulnerabilities with regard to the Processing of Customer Personal Data;
(m) provide employee and contractor security awareness training to ensure ongoing capabilities to carry out the security measures prescribed under this Addendum.

ANNEX III

LIST OF AUTHORISED SUBPROCESSORS

Please see: https://www.skillable.com/company/legal-and-security/subprocessors/

ANNEX IV

UK INTERNATIONAL DATA TRANSFER ADDENDUM TO THE EU COMMISSION STANDARD CONTRACTUAL CLAUSES

VERSION B1.0, in force 21 March 2022

Part 1: Tables

Table 1: Parties:

Start DateAs set out in the Principal Agreement
The PartiesAs set out in the Principal Agreement

Table 2: Selected SCCs, Modules and Selected Clauses

Addendum EU SCCs
The Approved EU SCCs, including the Appendix Information and with only the following modules, clauses or optional provisions of the Approved EU SCCs brought into effect for the purposes of this Addendum:
ModuleModule in operationClause 7 (Docking Clause)Clause 11 (Option)Clause 9a (Prior Authorization or General Authorization)Clause 9a (Time Period)Is personal data received from the Importer combined with personal data collected by the Exporter?
2YES if Customer is ControllerYESNOGENERAL15 daysn/a
3YES if Customer is ProcessorYESNOGENERAL15 daysn/a

Table 3: Appendix Information

“Appendix Information” means the information which must be provided for the selected modules as set out in the Appendix of the Approved EU SCCs (other than the Parties), and which for this Addendum is set out in:

Annex I Part A: List of Parties: the Principal Agreement
Annex I Part B: Description of Transfer: ANNEX I Part B
Annex II: Technical and organizational measures including technical and organizational measures to ensure the security of the data: ANNEX II
Annex III: List of Sub-processors: ANNEX III

Table 4: Ending this Addendum when the Approved Addendum Changes

Ending this Addendum when the Approved Addendum changesWhich Parties may end this Addendum as set out in Section 19:

- Importer or Exporter

Part 2: Mandatory Clauses

Mandatory ClausesMandatory Clauses of the Approved Addendum, being the template Addendum B.1.0 issued by the ICO and laid before Parliament in accordance with s119A of the Data Protection Act 2018 on 2 February 2022 (https://ico.org.uk/media/for-organisations/documents/4019539/international-data-transfer-addendum.pdf), as it is revised under Section 18 of those Mandatory Clauses.

ANNEX V

MODEL CLAUSES AMENDMENTS FOR SWITZERLAND Where the law of Switzerland applies to the transfer of Customer Personal Data hereunder, the applicable Model Clauses are incorporated by reference herein and amended as follows: a. All references to Regulation (EU) 2016/679 of the European Parliament and of Council of 27 April 2016 on the protection of natural persons with regard to the Processing of personal data and on the free movement of such data (“GDPR”) must be interpreted as references to the Swiss Data Protection Act in the context of data transfers abroad that are subject to the Swiss Data Protection Act. b. Any references to a data supervisory authority shall refer to the Swiss Federal Data Protection and Information Commissioner; and c. With regard to Clauses 17 and 18, these clauses shall be governed by the laws of Switzerland and the parties agree to the jurisdiction of the courts of Switzerland with regard to any disputes that arise from the Standard Contractual Clauses.

About Skillable

Skillable is a hands-on training and virtual labs platform that helps you accelerate product adoption, validate job readiness and boost confidence across your employees, customers and partners at scale.

Virtual lab use cases

Types of software training environments

Since 2004, more than 400 companies have trusted Skillable to launch more than 50 million labs to help accelerate product adoption and validate job readiness. See how you can too.

It’s time to finally connect learning to work outcomes.

Trusted and proven

Skillable is the 19-time G2 leader in "Virtual IT Labs" based on end user reviews.
Skillable is named a G2 leader in delivering "Best Results" for hands-on training and virtual IT labs based on hundreds of end user reviews.
Skillable is G2's "Most Implementable" for hands-on training and virtual IT labs based on hundreds of end user reviews.
Skillable a Training Industry Top 20 Company for Experiential Learning Technology
Skillable is a Training Industry Top 20 company for IT and Technical Training
Skillable is on the GSV150 list for the Most Transformational Growth Companies In Digital Learning and Workforce Skills