Data Processing Addendum

Last Updated: December 30, 2025 This Data Processing Addendum (“DPA”) is entered into between SwineTech, Inc., on behalf of itself and any Affiliates that are providing services to Customer (collectively for the purposes of this DPA and except where otherwise indicated, (“SwineTech”); and the organization or business identified in the applicable Order Form, on behalf of itself and its Affiliates (collectively for the purposes of this DPA and except where otherwise indicated, “Customer”). This DPA forms a part of and is incorporated into the Agreement (defined below). Capitalized terms used but not defined in this DPA shall have their meanings set forth in the Agreement.
  1. Definitions
  • Affiliate” means any entity that is controlled by a party to this Agreement, so long as the control exists. “Control” means direct or indirect control of more than 50% of the shares or other equity interests of the subject entity entitled to vote in the election of directors (or, in the case of an entity that is not a corporation, for the election or appointment of the corresponding managing authority). As to Customer, any reference to “Affiliate” herein is strictly limited to those Affiliates of Customer that qualify as a Controller with respect to the Customer Data and are permitted to use the Services pursuant to the Agreement, but have not signed their own Sales Order and are not a “Customer” as defined under the Agreement.
  • Agreement” means the agreement between the parties, together with any related statements of work, purchase orders, quotes, or order forms, pursuant to which SwineTech has agreed to provide the Services (as defined therein) to Customer, and which may require SwineTech to Process Personal Data on behalf of Customer.
  • Controller” means the entity that determines the purposes and means of the Processing of Personal Data.
  • Customer Data” means any and all Personal Data that SwineTech Processes on behalf of Customer or any Customer Affiliate in the course of providing the Services.
  • Data Protection Laws” means all laws and regulations applicable to the Processing of Customer Data by SwineTech under the Agreement, including, where applicable, but not limited to: (a) Regulation 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of Personal Data and on the free movement of such data (General Data Protection Regulation) (“GDPR”); (b) GDPR as it forms parts of the United Kingdom domestic law by virtue of Section 3 of the European Union (Withdrawal) Act 2018 (“UK GDPR”); and (c) the California Consumer Privacy Act, as amended and together with any implementing regulations (“CCPA”); in each case, as may be amended, superseded, repealed, consolidated, or replaced, as well as any national implementations or derogations of the same.
  • “Data Subject” means an identified or identifiable natural person about whom Personal Data may be Processed under this DPA.
  • “Personal Data” means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular individual or household. This definition includes “Personal Data,” “Personal Data,” or “Personally Identifiable Information,” as defined by any applicable Data Protection Laws. Personal Data does not include information or data that has been Processed in such a manner that no longer identifies, relates, describes, or is capable of being associated or linked with a particular Data Subject, consistent with the requirements for de-identification or anonymization under applicable Data Protection Laws.
  • Process,” “Processes,” or “Processing” means any operation or set of operations which is performed upon Personal Data, whether or not by automatic means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
  • Processor” means an entity that Processes Personal Data on behalf of the Controller.
  • Security Incident” means any unauthorized or unlawful breach of security leading to the accidental or unlawful destruction, loss, or alteration of, or unauthorized disclosure of, or unauthorized access to Customer Data that is Processed by SwineTech on behalf of Customer in providing the Services in a manner that compromises the security, integrity, or confidentiality of such Customer Data.
  • Sub-processor” means any Processor engaged by SwineTech to assist in Processing Customer Data with respect to providing the Services.
  1. Scope and Applicability. This DPA applies where and only to the extent that SwineTech Processes Customer Data in the course of providing the Services. With respect to any Customer Data, as between SwineTech and Customer, Customer is the Controller and SwineTech is the Processor. SwineTech may Process Customer Data on behalf of Customer solely in accordance with the terms of the Agreement, this DPA, and Customer’s lawful instructions. SwineTech shall inform the Customer if, in SwineTech’s opinion, an instruction issued by Customer violates Data Protection Laws. SwineTech shall be entitled to suspend the corresponding instruction until it has been confirmed or changed by Customer.
  2. The “Business Purpose” for SwineTech’s Processing of Customer Data on Customer’s behalf is identified in Annex A. Unless otherwise specified in the applicable Agreement, the duration of processing, the nature and purpose of the processing, the types of Customer Data and the categories of Data Subjects processed under this DPA are further specified in Annex A.
  3. Customer Representations and Warranties. Customer hereby represents and warrants that it: (a) will comply with its obligations under all Data Protection Laws with respect to all Customer Data and any Processing instructions it issues to SwineTech; (b) has a lawful basis to disclose the Customer Data to SwineTech; (c) has any and all consents, authorizations, rights, and authority necessary to transfer or disclose, or permit SwineTech to Process, any and all Customer Data in connection with the Agreement; and (d) will have sole responsibility for the accuracy, quality, and legality of any and all Customer Data Processed by SwineTech. Customer will promptly notify SwineTech if it is unable to comply with any of its obligations hereunder.
  4. Security. SwineTech shall implement and maintain throughout the term of the DPA, in accordance with industry practice, appropriate technical and organizational measures, including the measures referred to in Art. 32 GDPR, to protect Customer Data from Security Incidents and to preserve the security and confidentiality of the Customer Data, including but not limited to such measures identified in Annex B (“Security Measures”). Customer acknowledges that the Security Measures are subject to technical progress and development and that SwineTech may update or modify the Security Measures from time to time provided that such updates and modifications do not result in the degradation of the overall security of the Services purchased by Customer.
  5. Sub-Processors. Customer acknowledges and expressly agrees that SwineTech may retain its Affiliates or certain third parties as Sub-processors to Process Customer Data in order to provide the Services. Customer hereby authorizes SwineTech to engage the Sub-processors set forth in Annex C (List of Sub-Processors).  Customer shall have notification rights and rights to object to such Sub-processors in accordance with Annex C.   Prior to a Sub-processor’s Processing of Personal Data, SwineTech shall: (i) enter into an agreement with the Sub-Processors that imposes data protection terms on the Sub-Processors regarding the processing of Customer Data to the standard required by Data Protection Laws, and (ii) remain responsible for its compliance with the obligations subcontracted to the Sub-Processors.
  6. International Data Transfers. SwineTech may transfer Customer Data to, and process Customer Data in, the United States and anywhere else in the world where SwineTech or its Sub-processors maintain data processing operations, provided that such Processing is in accordance with Data Protection Laws, and Customer hereby consents to such transfers and Processing activity. The foregoing includes, without limitation, the express consent of Customer to the transfer of Customer Data outside of the European Economic Area or its member states, Switzerland, or the United Kingdom, as applicable. The parties agree that the data export solution identified in this DPA shall not apply if and to the extent that SwineTech adopts another alternative data export solution for the lawful transfer of Customer Data (as recognized under Data Protection Laws) (“Alternative Transfer Mechanism”), in which event, the Alternative Transfer Mechanism shall apply instead (but only to the extent such Alternative Transfer Mechanism extends to the territories to which Customer Data is transferred).
  7. Jurisdiction-Specific Provisions. In addition to the terms of this DPA, the following apply, where applicable, and control, if applicable and the subject of a conflict with the other terms of this DPA:
    • GDPR To the extent legally required, by entering into this DPA, Customer and SwineTech are deemed to have signed the Standard Contractual Clauses approved by the European Commission in Commission Decision 2021/914 dated 4 June 2021 (as amended and updated from time to time) (“EU SCCs”), which form part of this DPA and (except as described in Sections 8(c) and (d) below) will be deemed completed as follows:
      1. Module 2 of the EU SCCs applies to transfers of Customer Data from Customer (as a Controller) to SwineTech (as a Processor), and Module 3 of the EU SCCs applies to transfers of Customer Data from Customer (as a Processor) to SwineTech (as a Subprocessor);
      2. Clause 7 of the EU SCCs (the optional docking clause) is not included;
      3. Under Clause 9 of Modules 2 and 3 (Use of sub-processors), the Parties select Option 2 (General written authorization). The initial list of Subprocessors is set forth in Annex C of this DPA and the minimum time period for prior notice of sub-processor changes shall be as set forth in Annex C;
      4. Under Clause 17 of Modules 2 and 3 (Governing law), the Parties choose Option 1 (the law of an EU Member State that allows for third-Party beneficiary rights). For the EU SCCs generally, the Parties select the law of Spain;
      5. Under Clause 18 of the EU SCCs (Choice of forum and jurisdiction), the Parties select the courts of Spain;
      6. Annex I(A) and I(B) of the EU SCCs is completed as set forth in Annex A of this DPA;
      7. For Annex I(C) of Modules 2 and 3 (Competent supervisory authority), the Parties shall follow the rules for identifying such authority under Clause 13 and, to the extent legally permissible, select the Spanish Data Protection Agency (AEPD).
      8. Annex II of Modules 2 and 3 (Technical and organizational measures) is completed with Annex B of this DPA; and
      9. Annex III of Modules 2 and 3 (List of subprocessors) should be deemed completed by Annex C.
  • UK GDPR. To the extent legally required, by entering into this DPA, the Parties are deemed to be signing the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner’s Office, located at https://ico.org.uk/media/for-organisations/documents/4019539/international-data-transfer-DPA.pdf and completed as set forth herein (“UK SCCs”), which form part of this DPA and take precedence over the rest of this DPA as set forth in the UK SCCs. The Tables within the UK SCCs are deemed completed as follows:
    1. Table 1: The Parties’ details shall be the Parties and their Affiliates to the extent any of them is involved in such transfer, as set forth on Annex A, and the Key Contact shall be the contacts set forth in the Agreement.
    2. Table 2: The Approved EU SCCs referenced in Table 2 shall be the EU SCCs as executed by the Parties and completed in Section 8(b) of this DPA.
    3. Table 3: Annexes I and II are set forth in Annexes A and B, respectively. Annex III completed with Annex C.
    4. Table 4: Either Party may end this DPA as set out in Section 19 of the UK SCCs.
    5. By entering into this DPA, the Parties are deemed to be signing the UK SCCs, including the Mandatory Clauses of the Approved Addendum, being the template Addendum B.1.0 issued by the ICO and laid before Parliament in accordance with s119A of the Data Protection Act 2018 on 2 February 2022, as it is revised under Section ‎18 of those Mandatory Clauses.
  • FADP. For transfers of Customer Data that are subject to the FADP, the EU SCCs form part of this DPA as set forth in Section 8(a) of this DPA, but with the following differences to the extent required by the FADP: (i) references to the GDPR in the EU SCCs are to be understood as references to the FADP insofar as the data transfers are subject exclusively to the FADP and not to the GDPR; (ii) references to personal data in the EU SCCs also refer to data about identifiable legal entities until the entry into force of revisions to the FADP that eliminate this broader scope; (iii) term “member state” in EU SCCs shall not be interpreted in such a way as to exclude data subjects in Switzerland from the possibility of suing for their rights in their place of habitual residence (Switzerland) in accordance with Clause 18(c) of the EU SCCs; and (iv) the relevant supervisory authority is the Swiss Federal Data Protection and Information Commissioner (for transfers subject to the FADP and not the GDPR), or both such Commissioner and the supervisory authority identified in the EU SCCs (where the FADP and GDPR apply, respectively).
  • California. This section supplements the other terms and conditions of this DPA. For the purposes of this section, all terms herein that are given a meaning by the CCPA (other than those terms used to refer to the applicable parties) shall be considered defined in accordance with the CCPA. SwineTech shall not sell or share any personal information collected pursuant to this DPA and shall process such personal information solely for the business purposes specified herein and for no other purposes. SwineTech is prohibited from retaining, using, or disclosing personal information for any purpose other than those specified in this DPA or as otherwise permitted by the CCPA. SwineTech is further prohibited from retaining, using, or disclosing such personal information for any commercial purpose other than the business purposes specified herein, or outside the direct business relationship with Customer, unless expressly permitted by the CCPA. SwineTech shall not combine or update personal information collected under this DPA with personal information collected from its own interactions with the consumer or from other sources, unless expressly permitted by the CCPA. SwineTech shall comply with all applicable provisions of the CCPA and provide the same level of privacy protection as required of Customer, including implementing reasonable security procedures and cooperating with Customer in responding to consumer requests. Customer shall have the right to take reasonable and appropriate steps to ensure that SwineTech uses personal information collected pursuant to this DPA in a manner consistent with Customer’s obligations under the CCPA. SwineTech shall notify Customer if it determines it can no longer meet its obligations under the CCPA. Customer may take reasonable steps to stop and remediate any unauthorized use of personal information. SwineTech shall assist Customer in complying with consumer requests under the CCPA. SwineTech shall enter into written agreements with its subcontractors that comply with the CCPA.
  1. Confidentiality. SwineTech shall ensure that any person who is authorized by SwineTech to Process Customer Data shall be under an appropriate obligation of confidentiality (whether a contractual or statutory duty), with respect to such Personal Data.
  2. Security Incident. In the event that SwineTech becomes aware of a Security Incident, SwineTech will notify Customer without undue delay within forty-eight (48) hours of discovery and shall provide timely information relating to the Security Incident as it becomes known or as is reasonably requested by Customer, unless otherwise prohibited by law or otherwise instructed by a law enforcement or supervisory authority. Following such notification, SwineTech will take reasonable steps to mitigate the effects of the Security Incident and provide reasonable assistance and cooperation regarding any notifications that Customer is legally required to send to affected Data Subjects and regulators.
  3. Security Reports and Audit Obligations. SwineTech shall provide written responses (on a confidential basis) to all reasonable requests for information made by Customer that Customer (acting reasonably) considers necessary to confirm SwineTech’s compliance with this DPA as well as applicable Data Protection Laws. SwineTech may satisfy the audit obligation by providing Customer with attestations, certifications and summaries of audit reports conducted by accredited third party auditors evaluating Customer’s practices against acceptable standards. If such attestations, certifications and summaries do not reasonably address Customer’s concerns, Customer may elect to audit technical and organizational measures taken by SwineTech and shall document the results. Audits by Customer will be reasonable in scope for the relevant subject matter and subject to the following terms: (a) the audit will be at Customer’s expense; (b) the audit will be pre-scheduled in writing with SwineTech and will be performed not more than once a year (except as required by applicable law or mutually agreed upon for exigent circumstances); and (c) the auditor will execute a non-disclosure and non-competition undertaking on terms acceptable to SwineTech.
  4. Customer Security Responsibilities. Notwithstanding anything herein to the contrary, Customer agrees that except as provided by this DPA, Customer is responsible for its secure use of the Services, including securing its account authentication credentials, protecting the security of Customer Data when in transit to and from the Services, ensuring the Services are not used in a manner that violates applicable laws, and taking any appropriate steps to securely encrypt or backup any Customer Data uploaded to the Services. SwineTech’s will be liable for a Security Incident subject to the following conditions: (a) the Security Incident is caused by a violation of SwineTech’s or its Sub-processor’s obligations set forth in this DPA (including violation of Data Protection Laws); and (b) all liability of SwineTech excludes liability arising from or caused by the acts or omissions of Customer, or any person acting on behalf of or jointly with Customer.
  5. Information and Assistance. To the extent required by an applicable Data Protection Law, SwineTech will cooperate with Customer in compiling necessary records of processing activities for Customer as well as in the performance of necessary data protection impact assessments of Customer or subsequent consultation with a data protection supervisory authority or regulator. SwineTech may charge a reasonable fee for any such assistance, as permitted by applicable law.
  6. Data Subject Requests. To the extent that Customer is unable to independently access the relevant Customer Data within the Services, SwineTech shall (to the extent permitted by law, at Customer’s expense) taking into account the nature of the Processing, provide reasonable cooperation to assist Customer by appropriate technical and organizational measures, in so far as is possible, to respond to any requests from individuals or applicable data protection authorities relating to the processing of Customer Data under the Agreement. In the event that any such request is made directly to SwineTech, Customer acknowledges and agrees that SwineTech shall not respond to such communication directly without Customer’s prior authorization, unless legally compelled to do so.
  7. Subpoenas and Court Orders. If a law enforcement agency sends SwineTech a demand for Customer Data (for example, through a subpoena or court order), SwineTech shall give Customer reasonable notice of the demand to allow Customer to seek a protective order or other appropriate remedy unless SwineTech is legally prohibited from doing so.
  8. Return or Disposal of Data. Upon termination or expiration of the Agreement for any reason, SwineTech will return or destroy Customer Data (including copies) in its possession or control at Customer’s request and choice in accordance with the Agreement. Notwithstanding, this requirement shall not apply to the extent SwineTech is required by applicable law to retain some or all of the Customer Data.
  9. Customer Affiliates. Customer shall cause its Affiliates to be bound by the obligations under this DPA and, to the extent applicable, the Agreement. For the avoidance of doubt, a Customer Affiliate is not and does not become a party to the Agreement, unless the Agreement specifically provides otherwise. All access to and use of the Services by any Customer Affiliates must comply with the terms and conditions of this DPA and any violation of the terms and conditions of this DPA by a Customer Affiliate shall be deemed a violation by Customer. The entity (whether Customer or its Affiliate) that is the contracting party to the Agreement (“Contracting Party”) shall remain responsible for coordinating all communication with SwineTech under this DPA and be entitled to make and receive any communication in relation to this DPA on behalf of its Affiliates. To the extent any applicable Data Protection Law requires that a Customer Affiliate be entitled to exercise the rights and seek remedies under this DPA, the parties agree that (a) the Contracting Party is the sole entity entitled to exercise any such right or seek any such remedy on behalf of its Affiliates, and (b) the Contracting Party shall exercise any such rights under this DPA in a combined manner for itself and all of its Affiliates together, not individually.
  10. Limitation of Liability. Subject to the application of, and limitations set by, any Data Protection Law applicable to the specific claim or liability at issue: Each party’s and all of its Affiliates’ liability, taken together in the aggregate, arising out of or related to this DPA, whether in contract, tort or under any other theory of liability, is subject to the limitations and exclusions of liability in the Agreement, and any reference in provisions to the liability of a party means the aggregate liability of that party and all of its Affiliates under the Agreement and the DPA together. For the avoidance of doubt, SwineTech and its Affiliates’ total liability for all claims from the Customer and all of its Controller Affiliates arising out of or related to the Agreement and the DPA shall apply in the aggregate for all claims under both the Agreement and the DPA.
  11. Miscellaneous. To the extent applicable, the parties agree that by entering into and executing this DPA, the EU SCCs, the UK SCCs, and all Annexes constitute legally binding contracts between the parties and are hereby deemed to be signed by the parties. If there is any conflict between this DPA and the Agreement, this DPA shall prevail to the extent of that conflict. Unless otherwise provided for in this DPA or required by applicable Data Protection Law, this DPA shall be governed by and construed in accordance with governing law and jurisdiction provisions in the Agreement. Any disputes between the parties arising under this DPA are to be handled as set out in the Agreement. Customer acknowledges and agrees that SwineTech may, upon notice to Customer, amend the terms of this DPA, including any Annex, to the extent reasonably required to comply with any applicable law, applicable regulation, a court order or guidance issued by a governmental regulator or agency.
IN WITNESS WHEREOF, by entering into the Agreement, the parties have caused this DPA to be executed by their authorized representative and this DPA shall be effective on the date of the Agreement. ANNEX A – DETAILS OF PROCESSING
  • List of Parties:
**For the purposes of the EU SCCs, this information constitutes the details of “Annex 1.A”. The “Customer” as defined in the DPA is the “Exporter.” SwineTech, Inc. is the “Importer.” The parties’ details are set forth in the Agreement.
  • Details of Processing:
**For the purposes of the EU SCCs, this information constitutes the details of “Annex 1.B”.
  • Categories of Data Subjects. The Data Subjects whose Personal Data may be Processed and/or transferred as Customer Data includes:
Authorized Users and Other Customer Personnel: Any employees, contractors, or other third parties who are authorized under the Agreement to use the Services or are otherwise engaged by Customer.
  • Categories of Personal Data: The categories of Personal Data that may be Processed and/or transferred as Customer Data includes:
Authorized Users: Identification and contact data (name, address, title, username); employment details (employer, job title, geographic location, area of responsibility); details related to use of the Services (chat logs, information submissions or transmissions, images or file uploads); IT related data (computer ID, user ID, password, IP address, log files).
  • Special categories of data (if appropriate): SwineTech and/or its Sub-processors do not process any special categories of Personal Data.
  • Frequency of the Transfer: Continuously during Customer’s use of the Services, consistent with the terms of the Agreement.
  • Nature of the Processing: The Customer Data transferred will be Processed in accordance with SwineTech’s Privacy Policy and the Agreement and any Sales Order and may be subject to the following processing activities:
  • storage and other processing necessary to provide, maintain and improve the Services provided to Customer;
  • the sending of production and other business data to third parties (e.g., the Customer’s suppliers, vendors, advisory professionals), as directed by the Customer;
  • to provide assistance and technical support to the Customer; and
  • disclosures in accordance with the Agreement, as compelled by law.
  • Purposes of Transfer and Processing: For the purposes of: (i) providing the services described in the Agreement, (ii) to perform any steps necessary for the performance of its obligations under the Agreement, (iii) as initiated by any of Customer’s authorized users in their use of the Services, (iv) to comply with other reasonable and lawful instructions provided by Customer.
  • Period for which Personal Data will be retained, or the applicable criteria to determine that period: For the period necessary to perform the Services and otherwise as may be required by the Agreement or applicable law.
  • Transfers to Sub-processors: See details of Annex C.
  • Competent Supervisory Authority (if applicable):
**For the purposes of the EU SCCs, this information constitutes the details of “Annex 1.C”. Spanish Data Protection Agency (AEPD) ANNEX B – TECHNICAL AND ORGANIZATIONAL MEASURES INCLUDING TECHNICAL AND ORGANIZATIONAL MEASURES TO ENSURE THE SECURITY OF THE DATA Below is a description of the technical and organizational measures we implement for data protection and security. SwineTech carries out regular checks to ensure that these measures continue to provide an appropriate level of security. It is the controller’s obligation to request assistance from the processor if they believe further measures are necessary. The parties acknowledge that the measures outlined below take due account of the state of the art, the costs of implementation, the nature, scope, context and purpose(s) of processing and the risks involved in the processing for the data subject. These measures are commensurate to the nature, scope, context, and purposes of SwineTech’s products and services and provide an appropriate level of data protection as required by Data Protection Laws. Measures for ensuring accountability
  • Security Function: SwineTech has designated personnel as security managers tasked with responsibility for development, implementation, and maintenance of SwineTech’s information security practice.
Measures for internal IT and IT security governance and management
  • Network security: SwineTech relies on the network protection features of its hosting provider to protect Personal Data  and to safeguard from threats. SwineTech also conducts independent pen tests and periodic assessment of security setup.
Measures of pseudonymisation and encryption of personal data; Measures for the protection of data during transmission and storage
  • Encryption: SwineTech encrypts data at rest and uses secure protocols to connect Customer’s systems and uses HTTPS by default for internet traffic.
Measures for ensuring ongoing confidentiality, integrity, availability and resilience of processing systems and services
  • Information security policy: SwineTech has implemented information security policies that mandate the use of appropriate technical and organizational security measures in SwineTech’s organization to protect Personal Data in its possession or control against unauthorized and unlawful processing and against accidental loss, damage or destruction as well as appropriate measures in the event of an actual or suspected data or security breach.
  • Access controls: SwineTech has implemented technical access controls that restrict access to Personal Data it processes to duly authorized persons only, who are permitted to access Personal Data only to the extent necessary for the performance of their duties.
Measures for user identification and authorisation
  • Usernames / passwords: Access to Personal Data is controlled through access privileges (described above), usernames and confidential passwords.
Measures for ensuring the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident
  • Disaster recovery / business continuity: SwineTech has implemented appropriate disaster recovery and business continuity plans that ensure the availability, security, integrity and (where necessary) restoration of the Personal Data on the occurrence of a business interruption event.
Measures for ensuring the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident
  • Back-up: SwineTech has taken and will continue to take regular back-ups of the Personal Data that it processes on behalf of Customer. Data back-ups are stored securely at a different geographical location and will be available for data restoration in the event of catastrophic system failure and non-catastrophic system failure or user error.
Processes for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures in order to ensure the security of the processing
  • Audit: SwineTech will audit its compliance with its information security policies on a routine basis. Any remedial measures identified as necessary following an audit will be implemented.
Measures for data minimization; data erasure; and limited retention of data
  • Secure Disposal: SwineTech has implemented policies and procedures regarding the disposal of Personal Data, and tangible property containing Personal Data within our possession or control, taking into account available technology so that Personal Data cannot be practicably read or reconstructed upon secure disposal. SwineTech relies on secure deletion and database record deletion to delete or purge customer data. Deleted data is sanitized via disk wipe.
  • Data Retention Policies: SwineTech honors (or deploys its Services in a way that facilitates) Customer’s instructions for removing access for Customer personnel who are terminated or no longer authorized.
Measures for ensuring data quality
  • Data Quality Checks: We regularly report to Customer on any errors with integrations to Customer systems.
Measures for ensuring events logging
  • Log Safeguards: Logs are in place for our cloud storage systems. Access to logs is restricted to pre-approved authorized personnel only.
Measures for certification/assurance of processes and products
  • Routine Testing: SwineTech engages in routine testing of is information security systems, consistent with industry standards for its type of Services.
ANNEX C – LIST OF SUB-PROCESSORS Last Updated: December 30, 2025 Below is a current list of SwineTech’s Sub-processors. Not all Sub-processors process Personal Data of all types. SwineTech may update this list as Sub-processors are added or deleted and will maintain a current draft of the Sub-processor list at this webpage. SwineTech will update this online list publicly and regularly to keep all of its customers and prospective customers informed. SwineTech will also provide notice of new a Sub-processors specific to Customer in a separate written update to Customer. To the extent a new Sub-processor is added in an update, Customer may object in writing to the processing of its Customer Data by the new Sub-processor within fifteen (15) days following the update and such objection shall describe the customer’s legitimate reason(s) for objection. If Customer does not object during such time period, the new Sub-processor shall be deemed approved. If Customer objects to the use of a new Sub-processor pursuant to the process provided hereunder, SwineTech shall have the right to cure the objection through one of the following options (at SwineTech’s reasonable election) within sixty (60) days following Customer’s objection: (a) SwineTech will cease to use the new Sub-processor with regard to Customer Data; (b) SwineTech will take the corrective steps requested by Customer in its objection and proceed to use the Sub-processor to process Customer Data; or (c) SwineTech may cease to provide or Customer may agree not to use (temporarily or permanently) the particular aspect of a Service that would involve use of the Sub-processor to process Customer Data.  
Sub-processor: Details of Processing: Location of Processing: Website:
Amazon Web Services Servers and network infrastructure U.S., Canada, Germany, Ireland https://aws.amazon.com  
       
       
       
       
       
       
       
       
To the extent Customer has engaged an SwineTech partner in connection with the Agreement, such partner may in some cases be a subprocessor under the Agreement. SwineTech partners are participants in SwineTech’s partner program, are independent third parties, and are not Affiliates of SwineTech; the use of “partner” in this context does not refer to a legal partnership or any similar arrangement under which SwineTech or SwineTech partner may bind or act on behalf of one another.