This Data Processing Addendum ("DPA") forms part of the Replicas Terms of Service or other agreement that incorporates it and governs Customer's use of the Replicas cloud service ("Agreement"). It is between Replicas Group, Inc. ("Replicas") and the person or legal entity identified as the customer in the applicable account or order ("Customer"). Replicas and Customer are each a "Party" and together the "Parties".
Customer accepts this DPA, including its applicable transfer terms, by affirmatively accepting the Agreement that incorporates this DPA. A person accepting for an entity represents that they have authority to bind that entity. Replicas agrees to this DPA by providing the Service under that acceptance. The DPA takes effect upon that acceptance and continues for as long as Replicas processes Customer Personal Data. No separate signature is required. This is Replicas' standard, non-negotiable online DPA; Customer's purchase orders, annotations or proposed changes do not modify it. A separately executed data processing agreement expressly covering the same processing prevails to the extent it conflicts with this DPA.
Definitions and scope
1.1 "Service" means the Replicas cloud platform, including its web application, mobile application and API, provided under the Agreement. "Customer Personal Data" means personal data in information, content or credentials submitted to, accessed by, generated by or stored in the Service on Customer's behalf. "Data Protection Laws" means the privacy and data protection laws applicable to that processing, including, where applicable, the EU General Data Protection Regulation ("EU GDPR"), the UK General Data Protection Regulation ("UK GDPR") and Data Protection Act 2018, the Swiss Federal Act on Data Protection ("FADP"), and the California Consumer Privacy Act as amended, including its implementing regulations ("CCPA"). "EEA" means the European Economic Area. The terms personal data, processing, controller, processor and data subject have the meanings given by applicable Data Protection Laws.
1.2 Replicas acts as Customer's processor or, where Customer is a processor for another controller, its subprocessor. Customer determines or conveys the documented instructions for processing and is responsible for obtaining any required controller authorization. Appendix A describes the processing; Appendix B describes the security measures. This DPA applies only to the extent Replicas processes Customer Personal Data on Customer's behalf.
1.3 Personal data that Replicas processes as an independent controller to administer its own customer relationship, collect payment, maintain legally required business records or comply with its own legal obligations is governed by applicable law and the Replicas Privacy Policy. This distinction depends on the purpose and actual circumstances of processing; it does not remove Customer content, task processing or support access from this DPA or authorize independent use of that content.
Instructions, confidentiality and permitted use
2.1 Replicas will process Customer Personal Data only on Customer's documented instructions, including the Agreement, this DPA, Customer's configured tasks and settings, and its enabled integrations and selected model providers. Replicas may also process as required by applicable law, in which case it will inform Customer of that requirement before processing unless the law prohibits notice. Replicas will immediately inform Customer if, in its opinion, an instruction infringes applicable Data Protection Laws and may suspend the affected processing while the Parties address that instruction.
2.2 Replicas will protect Customer Personal Data as confidential information and restrict access to authorized persons as necessary for permitted processing or as required by law. Personnel authorized to process it must be bound by confidentiality obligations or an appropriate statutory duty of confidentiality.
2.3 Replicas will not use Customer Personal Data to train, develop or improve machine learning models or algorithms. Evaluation, maintenance and improvement of the Service software using Customer Personal Data are permitted only within Customer's instructions and applicable law. This provision does not authorize cross-customer profiling, independent reuse of Customer content or incompatible purposes.
2.4 Customer controls the third-party applications and AI providers it connects under its own accounts and credentials. Replicas' handling and transmission of Customer Personal Data to those recipients remain subject to this DPA. The recipients' processing under Customer's own accounts is governed by Customer's arrangements with them. A recipient that Replicas in fact engages to process Customer Personal Data on its behalf remains a Subprocessor, regardless of its label or integration method. Replicas does not make a blanket commitment about independently selected providers' training or retention practices.
2.5 Customer will comply with Data Protection Laws when giving instructions, establish the necessary lawful bases and provide required notices. Customer is responsible for its content, access permissions and use of connected services. The Service does not generally filter out sensitive personal data. Customer must assess the suitability of the documented safeguards for its use and may not use the Service for processing that requires protections or a separate agreement the Parties have not established. This DPA is not a HIPAA business associate agreement and does not by itself authorize regulated-sector processing.
Subprocessors
3.1 "Subprocessor" means a third party engaged by Replicas to process Customer Personal Data on its behalf. Customer generally authorizes the Subprocessors identified in Appendix C and the current register linked there. Replicas will impose, by written agreement, data protection obligations substantially the same as the applicable obligations in this DPA and remains responsible for each Subprocessor's performance of those obligations.
3.2 Replicas will maintain an up-to-date register identifying Subprocessors, their functions and processing locations. At least 30 calendar days before an additional or replacement Subprocessor begins processing Customer Personal Data, Replicas will update that register and send written notice to Customer's designated account or privacy-contact email, with information sufficient to assess the change. Merely posting an update does not replace that notice. Where Customer is a processor, it must promptly pass the notice to the relevant controller; Replicas will also provide notice directly to the controller where the applicable transfer terms require it and Customer supplies its contact details.
3.3 Customer may object in writing to founders@replicas.dev during that notice period on reasonable data protection grounds. Replicas will consider the objection in good faith and seek a commercially reasonable way to address it. If the objection cannot be resolved before the proposed engagement, the new Subprocessor will not process the objecting Customer's Personal Data unless the objection is resolved. Either Party may instead terminate the affected Service, with a refund of prepaid fees for the unused portion. That termination and refund is Customer's contractual remedy for an unresolved objection, without limiting rights under mandatory law or Appendix D.
Security and incidents
4.1 Replicas will implement and maintain reasonable and appropriate technical and organizational measures designed to protect the confidentiality, integrity and availability of Customer Personal Data, including Appendix B. It will regularly monitor compliance and will not materially diminish the overall security of the Service during the Agreement.
4.2 A "Security Incident" is a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data processed by Replicas. Replicas will notify Customer without undue delay after becoming aware of a Security Incident affecting Customer and will take reasonable steps to identify its cause, contain its effects and remediate it within Replicas' control.
4.3 Notice will be sent to Customer's designated account or privacy-contact email. As information becomes available, Replicas will provide the nature of the incident, the affected categories and approximate numbers of individuals and records where known, likely consequences, measures taken or proposed, and a contact for follow-up. Information may be provided in phases without undue further delay. Replicas will reasonably assist Customer with notifications required by Data Protection Laws. Notice is not an admission of fault or liability.
4.4 Unsuccessful attempts that do not compromise Customer Personal Data are not Security Incidents. Customer remains responsible for its own required regulator and individual notices, without limiting Replicas' independent legal duties. Customer must maintain current notice-contact information and protect its accounts and connected credentials.
Individual rights and compliance assistance
5.1 Taking into account the nature of processing, Replicas will assist Customer through appropriate technical and organizational measures, insofar as possible, with requests to exercise data protection rights that Customer cannot reasonably fulfil through the Service. If Replicas receives a request relating to Customer Personal Data directly, it will promptly notify Customer and will not respond substantively unless authorized by Customer or required by law. Where applicable, it will also cooperate with Customer's controller.
5.2 Taking into account the nature of processing and the information available to Replicas, Replicas will reasonably assist Customer with security obligations, data protection impact and similar assessments, and required consultations with regulators. To the extent applicable, this includes assistance with Customer's obligations relating to automated decision-making. Customer remains responsible for decisions it makes using the Service.
Information and audits
6.1 Replicas will make available information reasonably necessary to demonstrate compliance with this DPA. Customer should first use available security documentation, responses and independent audit reports, if any. Confidential materials may be subject to reasonable confidentiality safeguards. This DPA does not warrant that any particular audit report or certification is available.
6.2 If those materials are insufficient to demonstrate compliance, Replicas will allow and contribute to an audit, including inspection, by Customer or an independent auditor mandated by Customer. Except where law, a competent authority, a Security Incident or reasonable indications of noncompliance require otherwise, audits will occur no more than annually, on reasonable prior notice, during business hours, under a reasonable plan designed to minimize disruption and protect other customers' information and security.
6.3 Customer bears its audit costs and reasonable, agreed assistance costs, except where applicable law requires otherwise or the audit identifies Replicas' material noncompliance. Conditions, confidentiality arrangements and fees will not prevent or unreasonably delay a legally required audit, regulator access, or rights under Appendix D.
Return, deletion and retention
7.1 Customer may use supported downloads and deletion functions during the Agreement or request assistance at founders@replicas.dev. Supported exports include chats and files; complete account export is not entirely self-service. Deleting a single workspace is distinct from deleting persisted account records, saved files, media and memory.
7.2 Following termination or expiration of the affected Service, Replicas will, at Customer's choice, return or delete Customer Personal Data and delete existing copies, except where storage is required by applicable law. Customer should instruct Replicas to return data before termination; absent that instruction, Customer instructs Replicas to delete. Replicas will complete the requested return or deletion from active systems within 30 calendar days after termination or the applicable earlier account-deletion request. A later return request will be honored to the extent the data has not already been deleted; it does not extend the deletion period. A shorter legally required period prevails.
7.3 To the extent Customer Personal Data remains in backup copies, Replicas will isolate those copies from ordinary use, maintain the protections of this DPA, and permanently delete them through its deletion cycle no later than 90 calendar days after the corresponding active-system deletion. Backup data may be restored only for recovery or security purposes; any prior deletion instruction will be reapplied before the restored data is returned to ordinary use. These provisions do not permit retention where applicable law or the transfer terms require earlier deletion.
7.4 Data required by law to be retained will be limited to what the law requires, protected under this DPA and used only for that legal purpose, then deleted when the requirement ends. Replicas will confirm completion of deletion on request, including certification where required by the applicable Standard Contractual Clauses. Replicas will require the corresponding return or deletion by its Subprocessors. Copies held by services independently connected by Customer remain subject to Customer's arrangements with those services.
International transfers
8.1 Customer instructs Replicas to process Customer Personal Data in the United States and other locations disclosed under Section 3 and Appendix C, subject to Data Protection Laws and Appendix D. This DPA does not promise exclusive storage or access within a particular country.
8.2 A "Restricted Transfer" is a transfer of Customer Personal Data requiring a transfer safeguard under the EU GDPR, UK GDPR or FADP because an applicable adequacy decision or other lawful basis does not cover the transfer. Appendix D applies to relevant Restricted Transfers. Replicas will provide information reasonably necessary for required transfer assessments and cooperate in implementing necessary supplementary measures. If a transfer lacks a valid safeguard or a Party cannot comply with the applicable transfer terms, the affected transfer must be suspended until compliance is restored or the affected processing is terminated under those terms.
California processing
9.1 For Customer Personal Data subject to the CCPA, Replicas acts as Customer's service provider or contractor, or as a subcontractor in the applicable service-provider chain. Customer discloses the personal information only for the limited and specific business purposes and services described in Appendix A. Replicas will not sell or share that personal information; retain, use or disclose it outside the direct business relationship with Customer or for purposes other than the specified business purposes and services, except as permitted by the CCPA; or combine it with personal information from other sources except as permitted by the CCPA and consistent with this DPA.
9.2 Replicas will comply with applicable CCPA obligations, provide the same level of privacy protection required by the CCPA, and notify Customer if it determines that it can no longer meet those obligations. Replicas certifies that it understands and will comply with these restrictions. Customer may take reasonable and appropriate steps under Section 6 to ensure compliant use and, upon notice, to stop and remediate unauthorized use. Replicas will reasonably assist Customer in responding to applicable consumer requests and will notify Customer before engaging a subcontractor and bind that subcontractor by a written contract meeting applicable CCPA requirements.
Liability and relationship with the Agreement
10.1 The Agreement's exclusions and limitations of liability apply to claims under this DPA, subject to Section 10.2. This DPA does not create a separate or additional liability cap or a standalone indemnity. Any applicable indemnity in the Agreement continues on its own terms.
10.2 Nothing in this DPA limits liability to individuals for their data protection rights, liability that applicable law does not permit to be limited, or either Party's liability to the other for violating the Standard Contractual Clauses. No term of the Agreement or this DPA restricts rights, remedies, regulatory powers or protections that cannot be restricted under Appendix D.
10.3 In a conflict concerning processing, the mandatory transfer terms in Appendix D prevail, followed by this DPA and then the Agreement. The Agreement's governing-law and dispute-resolution provisions otherwise apply. An operational change, Privacy Policy statement or general change to the Terms of Service does not override this DPA's processing restrictions or Appendix D.
Versions and changes
11.1 The version identified in Customer's acceptance record applies to Customer. Replicas may update this DPA to reflect changes in law or the Service, but an update will not materially reduce the protection of Customer Personal Data. Replicas will retain a record of prior versions and give at least 30 calendar days' email notice of a material change, unless an earlier change is legally required; notice of an earlier legally required change will be given as soon as reasonably practicable.
11.2 Material changes require Customer's affirmative acceptance before they apply, except changes that mandatory law itself requires. Posting revised terms or Customer's silence does not constitute that acceptance. If Customer declines a change required to continue the affected Service lawfully, either Party may terminate that Service with a refund of prepaid unused fees. The existing DPA continues to protect retained Customer Personal Data. Subprocessor changes follow Section 3. The Standard Contractual Clauses and UK Addendum may be amended only as their mandatory terms permit.
Contact
Privacy, security and DPA requests: founders@replicas.dev. Replicas' technical contact is Saai Arora, CTO; its business contact is Connor Loi, CEO. Customer's authorized account administrator or designated privacy contact is the point of contact recorded in its account or order. Customer must keep that information accurate and current.
Parties and processing details
A.1 Customer / data exporter. The person or legal entity identified in the account or order that accepted the Agreement. Its name, address and authorized contact are those supplied in the account, billing, order or transfer-onboarding record. Its role is controller or processor as described in Section 1.2. Its relevant activities are its use of the Service and its instructions described below. Customer must supply accurate legal-entity, address, contact and role information and any required controller or supervisory-authority particulars before a Restricted Transfer. Those particulars form part of this Appendix.
A.2 Replicas / data importer. Replicas Group, Inc., 131 Continental Drive, Suite 305, Newark, Delaware 19713, United States. Contact: founders@replicas.dev, attention Connor Loi, CEO, or Saai Arora, CTO. Role: processor or subprocessor. Activities: providing the Service and the processing described below. Each Party intends its electronic acceptance under this DPA to sign and bind it to this Appendix, including Annex I of the applicable Standard Contractual Clauses, on the date recorded for that acceptance.
A.3 Subject matter, nature and purposes. Operating Customer's cloud workspaces and AI-agent tasks; receiving prompts, code, files, credentials and connected-application data; storing account and workspace state, saved history, files and memory; running tasks, editing code and files, testing and producing outputs; authenticating users and integrations; securing, monitoring and troubleshooting the Service; providing support and requested exports; and deleting data on instruction. Processing includes collection, recording, organization, storage, retrieval, use, transmission, restriction and erasure. Evaluation and software improvement are limited by Section 2.3. Processing does not include unrestricted reuse for Replicas' own purposes.
A.4 Individuals and data. Individuals may include Customer's users, employees, contractors, customers, prospects, business contacts, contributors and other people whose information appears in Customer content or connected systems. Data may include names, contact details, user and organization identifiers, roles, professional information, billing and subscription records, preferences, credentials and tokens, repository and integration metadata, prompts, chats, source code, documents, images, audio, video, memory summaries, device and IP information, logs and usage information. The actual subset is determined by Customer's use and instructions.
A.5 Sensitive data and safeguards. Credentials and confidential files may be processed. Customer-controlled content may also include health, biometric or genetic information, government identifiers, precise location, financial account details, racial or ethnic origin, religious or philosophical beliefs, political opinions, trade-union membership, sex life or sexual orientation, criminal-offence information, or children's information. Such data is not required for ordinary use. Customer must minimize its submission and comply with Section 2.5. Safeguards include encryption, isolated workspaces, credential-access restrictions, confidentiality, limited role-based access and incident procedures in Appendix B. Where the actual sensitive-data processing requires additional safeguards, that processing must not begin until they are established and documented; acceptance of this DPA alone does not supply them.
A.6 Frequency and duration. Processing and transfers occur continuously or on demand through Customer's tasks, API calls and automations for the duration of the affected Service and the limited return, deletion or legally required retention periods in Section 7. Inactive workspaces are scheduled for archive after seven days and archived workspaces for deletion after 30 days; workspace metrics are retained for 60 days and webhook events for 30 days. Those workspace-specific cycles do not describe the deletion of all persisted account data. Section 7 controls return and deletion at termination and on account-deletion requests.
A.7 Competent supervisory authority. For EU Standard Contractual Clauses, the authority is determined under Clause 13: the authority responsible for the exporter's GDPR compliance where it is established in an EEA Member State; otherwise the authority of the Member State where its Article 27 representative is established; or, where no representative is required, the authority of a Member State in which affected data subjects are located, as identified in Customer's transfer-onboarding record. The UK authority is the Information Commissioner; the Swiss authority is the Federal Data Protection and Information Commissioner where applicable. Selection of Irish SCC law does not itself select an Irish supervisory authority.
Technical and organizational measures
B.1 Authentication and access. The Service uses account authentication, organization membership, roles and permissions. Staff access is based on role and business need. Administrative, engineering and support personnel may access relevant Customer data for permitted administration, troubleshooting or support. Production remote access requires multi-factor authentication (MFA) and an approved encrypted connection. Access to in-scope systems is reviewed at least quarterly; provisioning follows role/function requirements or a documented, approved request. Access is removed during offboarding.
B.2 Encryption and keys. Public applications, APIs and provider connections use HTTPS/TLS. Hosting-platform controls encrypt production databases, object storage, workspace disks and logging systems at rest. Supabase Vault stores credentials in encrypted form, and the Service decrypts them when needed for an authorized task. Privileged key access is limited to authorized personnel with a business need.
B.3 Separation and networks. Customer workspaces run in isolated virtual machines with scoped access secrets. Network segmentation, firewalls and restricted production-network, operating-system and database access protect Customer data. Firewall rules and documented hardening standards are reviewed at least annually.
B.4 Development and vulnerabilities. Replicas maintains development-lifecycle and configuration-management procedures, internal code-security and dependency review, vulnerability monitoring and routine patching. External-facing systems undergo host-based vulnerability scanning at least quarterly; critical and high findings are tracked to remediation. Other findings are prioritized according to severity. This DPA does not promise a particular penetration-test cadence.
B.5 Logging and response. CloudWatch and Sentry support operational logging, alerts and error investigation; ClickHouse and PostHog support usage analysis. Administrative audit logs cover account and configuration changes. Incident-response procedures cover recording, investigation, containment, remediation and review and are tested at least annually. Personal data in logs and analytics remains subject to this DPA where processed on Customer's behalf; identifiers are not treated as anonymous merely because names are removed.
B.6 Continuity and recovery. Replicas maintains documented continuity, disaster-recovery and backup/recovery policies and tests its continuity and disaster-recovery plan at least annually. Infrastructure monitoring generates alerts for defined conditions. Backup retention and restored data are subject to Section 7. No particular recovery-time objective, recovery-point objective or continuous-availability service level is created by this DPA.
B.7 Personnel, devices and premises. Measures include confidentiality obligations, background checks where permitted, managed devices, password policies, anti-malware on relevant systems, offboarding controls, and security training within 30 days of joining and annually thereafter. Replicas relies on its infrastructure providers' physical-security controls and restricts authorized physical access where applicable.
B.8 Governance and vendors. Responsibilities for security controls are assigned; security policies, risk assessments and control self-assessments are reviewed at least annually. Before providing customer data to a new vendor, management reviews security and privacy risk, limits the data and access to what is needed, and requires appropriate written terms. Critical vendors are reviewed at least annually.
B.9 Minimization, correction and retention. Customers select submitted content and enabled integrations. Analytics/session-replay masking reduces exposure of private content. Eligible plans can disable saved chat and Canvas history; doing so also prevents new chat captures for memory and stops saved memory from loading. Repository files are stored separately, and this setting does not promise deletion of all data or retroactive purge. Replicas can locate accounts by email or user ID, correct account information, provide supported exports and assist with requests concerning persons mentioned in Customer content in coordination with Customer.
Subprocessor register
C.1 The following providers are authorized to the extent they process Customer Personal Data on Replicas' behalf for the functions described. Listing a provider does not classify all its activities as subprocessing. Replicas' current register at https://app.vanta.com/replicas.dev/trust/t8qlw1u4i067lqg7b4lh6q/subprocessors supplements this Appendix and must identify the actual applicable processing countries. Additions and replacements remain subject to Section 3. Customer-connected accounts and AI providers are treated under Section 2.4.
C.2 Infrastructure and operations. Amazon Web Services, Inc. — backend, operational logs and saved chats, files, media and memory; primary hosting in Ohio, United States. Supabase, Inc. — production database, authentication and encrypted credentials; primary database hosting in Ohio, United States. FoundryLabs, Inc. (E2B) — isolated virtual machines and memory jobs processing workspace code, files, prompts, outputs, commands and credentials. Vercel Inc. — web hosting and delivery, requests, sessions and delivery logs. Temporal Technologies, Inc. — scheduled and durable workflows, identifiers, status and workflow errors.
C.3 Analytics, diagnostics and mobile. ClickHouse, Inc. — analytics warehouse, user/workspace identifiers and usage metrics. PostHog, Inc. — product analytics and masked session replay. Functional Software, Inc. (Sentry) — errors, traces, request diagnostics and masked error replay. 650 Industries, Inc. (Expo) — mobile builds, updates and update/crash diagnostics.
C.4 Communications, billing and integrations. Resend (Plus Five Five, Inc.) — email delivery, contacts, message content and delivery records. Salesforce, Inc. (Slack) — internal support notifications and collaboration, including support content and account events. Stripe, Inc. — subscription billing and payment processing. Composio, Inc. — supported marketplace plugins, connected credentials, requests, responses, files and records.
C.5 Development, company services and compliance. GitHub, Inc. — Replicas development tooling and records. Google LLC (Google Workspace) — company identity, email and collaboration. Vanta Inc. — security and compliance monitoring and records. These providers are Subprocessors only for activities in which they process covered Customer Personal Data on Replicas' behalf; purely workforce or independent-controller processing is outside that classification.
C.6 Except for the primary Ohio deployments identified above, relevant countries are those specified in the register for each applicable service and processing activity, including remote access and downstream processing. Replicas will disclose the relevant countries before processing Customer Personal Data there. Engagement lasts while the relevant provider supplies its listed function, subject to Section 7's return and deletion obligations.
International transfer terms
D.1 EU Standard Contractual Clauses. For a Restricted Transfer subject to the EU GDPR for which the clauses may lawfully be used, the clauses in the Annex to Commission Implementing Decision (EU) 2021/914 of 4 June 2021 ("Standard Contractual Clauses" or "SCCs") are incorporated into and form part of this DPA. The authoritative text is available at https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj/eng. Customer is the exporter and Replicas is the importer. Module Two applies where Customer is a controller; Module Three applies where Customer is a processor. Only the module corresponding to the actual processing relationship applies. These clauses are not relied on as a transfer safeguard for importer processing outside their permitted scope; an alternative valid safeguard must be established before any such Restricted Transfer.
D.2 Selections. The optional docking clause in Clause 7 does not apply. Clause 9(a) uses Option 2, general written authorization, with 30 calendar days' prior written notice and the agreed list in Appendix C and its register. The optional independent-dispute-resolution provision in Clause 11(a) does not apply. Clause 17 uses Option 1 and Irish law. Clause 18(b) specifies the courts of Ireland. Data subjects retain the rights and forum protections granted by the SCCs.
D.3 Annexes and execution. Appendix A supplies Annex I.A and I.B, and A.7 supplies Annex I.C. Appendix B supplies Annex II, including the measures and assistance for individual rights. Appendix C and its register supply the agreed Subprocessor list and, where relevant, Annex III. Customer's actual account/order/transfer particulars identified in Appendix A form part of the annexes. The Parties' electronic acceptance under this DPA constitutes execution of the SCCs and Annex I. Required particulars, applicable safeguards and transfer assessments must be complete before a Restricted Transfer; online acceptance does not dispense with those requirements.
D.4 UK Addendum. For a Restricted Transfer subject to the UK GDPR, the ICO International Data Transfer Addendum to the EU Commission Standard Contractual Clauses, version B1.0 in force 21 March 2022, as revised under its Section 18 ("UK Addendum"), is incorporated. Its Mandatory Clauses apply without modification. The approved text is available at https://ico.org.uk/media2/migrated/4019539/international-data-transfer-addendum.pdf. For Table 1, the Parties, key contacts and details are those in Appendix A and the start date is the DPA acceptance date; electronic execution is as described there. For Table 2, the selected SCCs are the SCCs identified in D.1, with the relevant Module Two or Three and the selections in D.2. For Table 3, the Appendix Information is supplied by Appendices A, B and C as described in D.3. For Table 4, both the importer and exporter may end the UK Addendum in accordance with Section 19. Conflicts are resolved under Sections 9–11 of the UK Addendum, including the exception for SCC provisions giving greater protection to data subjects. Its Mandatory Clauses apply the laws and courts of England and Wales, with the data-subject forum rights they preserve.
D.5 Swiss transfers. For a Restricted Transfer subject to the FADP, the SCCs apply with the selections and annexes above and the adaptations necessary under the FADP. References to the GDPR include the FADP for the Swiss processing; references to the competent supervisory authority mean the Swiss Federal Data Protection and Information Commissioner for that processing. References to a Member State must not exclude data subjects in Switzerland from bringing proceedings in their place of habitual residence under Clause 18(c). Irish law and the courts of Ireland remain selected for interparty SCC claims, without restricting those Swiss data-subject rights. Where the EU GDPR also applies, its SCC protections and competent supervisory-authority provisions remain intact.
D.6 Mandatory protections. The SCCs and UK Addendum prevail over inconsistent terms. No liability limit, exclusive remedy, audit condition, choice of forum, change mechanism or other provision of the Agreement or this DPA modifies or restricts their mandatory terms. Replicas will comply with their applicable onward-transfer, government-access, transparency, complaint, suspension and deletion obligations. No Data Privacy Framework certification is represented or relied upon by this DPA.