Legal

Origin Data Processing Addendum

This Data Processing Addendum (“DPA”) is made part of the Origin Service Terms, or any other agreement for the use of the Origin Services, (“Agreement”) entered into between you and any company or entity that you are acting for (“You”), and Origin Technology, Ltd., and its subsidiaries and affiliates (“Origin”), each a “Party” and collectively the “Parties”, as of the date you entered into the Terms.

1. Background and Purpose

1.1) The Parties have entered into an Agreement under which Origin will deliver to You the Origin services (“Services”).

1.2) In the course of providing the Services to You under the Agreement, Origin may gain access to Personal Data, including without limitation Personal Data accessible through Your endpoints or submitted by You, or Your representatives or on Your behalf, to the Services. The details of processing, including Categories of Personal Data processed, are attached hereto as Annex 1.

1.3) The Parties enter into this DPA to ensure that any processing of Personal Data is carried out in accordance with the applicable Privacy Laws.

2. Definitions

Defined terms used but not defined herein shall have the same meaning as the Agreement. For purposes of this DPA:

2.1) “Personal Data” means all data related to an identified or identifiable person processed by Origin under this DPA;

2.2) “Privacy Laws” means applicable privacy, security and personal information protection laws and regulations in force from time to time, including, but not limited to, the European General Data Protection Regulation (EU 2016/679) (the “GDPR”); the UK GDPR from December 31st 2020 (“UK GDPR”); the Federal Data Protection Act of 19 June 1992 (Switzerland) and the revised Swiss Federal Data Protection Act effective September 1, 2023 (“Swiss FADP”); Personal Information Protection and Electronic Documents Act (Canada) (the “PIPEDA”); the California Consumer Privacy Act of 2018, as amended from time to time and California Privacy Rights Act of 2020 (collectively “CCPA”) as well as other relevant state privacy laws such as, without limitation, the Colorado Privacy Act, the Virginia Consumer Data Protection Act, the Connecticut Act Concerning Personal Data Privacy and Online Monitoring, the Utah Consumer Privacy Act, the Iowa Data Privacy Act, the Indiana Consumer Data Protection Act, the Montana Consumer Data Privacy Act, the Tennessee Information Protection Act, and the Texas Data Privacy and Security Act and any subsequent privacy laws enacted in the United States requiring data processing agreements (collectively “US Privacy Laws”);

2.3) “Standard Contractual Clauses” or “SCCs” means the applicable module of the standard contractual clauses for the transfer of personal data to third countries adopted pursuant to the European Commission’s Implementing Decision (EU) 2021/914 of 4 June 2021;

2.4) “UK IDTA” means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses (version B.1.0) issued by the UK Information Commissioner and laid before UK Parliament on 2 February 2022 in accordance with section 119A of the UK Data Protection Act 2018;

2.5) The terms “Controller”, “Data Controller”, “Data Processor”, “Data Subject”, “Processing”, “Processor”, “Personal Data Breach”, and where applicable “Business”, “Commercial Purpose”, “Consumer”, “Personal Information”, “Service Provider”, “Sell” and “Verifiable Consumer Request”, unless specifically defined otherwise herein, shall bear the respective meanings given to them in the applicable Privacy Laws.

3. Subject of this DPA and the Purpose of Processing

3.1) For the purpose of this DPA, You are the Data Controller of the Personal Data. In performing the obligations set out in the Agreement, Origin is the Data Processor and processes Personal Data on Your behalf. With respect to any Personal Data subject to the CCPA, the Parties acknowledge that You are a “Business” and Origin is a “Service Provider” as those terms are defined in the CCPA.

3.2) Origin shall process Personal Data in accordance with the applicable Privacy Laws, this DPA, and the Agreement, for the purposes of providing, enhancing, improving, updating, securing, analyzing, marketing, or upgrading the Services or developing new services or services related to or complementary to the Services. Origin may use machine-learning, large language model, and other artificial-intelligence components in the course of processing Personal Data to deliver detection, classification, summarization, and response capabilities; such processing does not result in decisions producing legal effects or similarly significant effects on Data Subjects without human review, and You remain responsible for any downstream automated decision-making You implement based on the outputs of the Services.

3.3) Data, signals, telemetry, detections, indicators of compromise, behavioral baselines, security findings, and analytics derived, observed, or produced by the Services that are not Personal Data, together with any data Origin has irreversibly de-identified and aggregated so that it can no longer reasonably be linked to an individual or to You (collectively, “Service Data” and “Aggregated Data”, respectively), are not Personal Data processed on Your behalf under this DPA, and Origin may use such Service Data and Aggregated Data as permitted under the Agreement, including to operate, secure, improve, train, and benchmark the Services and to publish aggregated threat intelligence.

3.4) Categories of Personal Data processed by Origin within Your endpoints are primarily designated by You, based on how You choose to use the Services and the scope of access You grant to Origin. The Services are not designed to process special categories of Personal Data (as defined in Article 9 of the GDPR), and You shall configure the Services and the endpoints on which Observability Agents are deployed to avoid the collection of such data. You acknowledge that endpoint telemetry collected in the ordinary course (e.g., process names, command-line arguments, authentication metadata, network metadata) may incidentally include information that is, in context, sensitive; You shall implement appropriate controls (including suppression and redaction features made available by the Data Processor) to minimize such collection.

4. Origin’s Obligations

4.1) In discharging its obligations under the Agreement, Origin shall perform the processing operations set out in this DPA.

4.2) Origin shall:

  • a) without undue delay, inform You of any facts affecting the fulfillment of their obligations under this DPA;
  • b) Process the Personal Data only on documented instructions from You;
  • c) Maintain the confidentiality of the Personal Data processed under this DPA. Origin shall ensure that persons authorized to process the Personal Data under this DPA have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. Origin shall train and educate all its personnel with access to Personal Data on the obligation to comply with Privacy Laws that are applicable to Origin as a service provider to the Data Controller;
  • d) Taking into account the nature of processing and the information available to Origin, assist You in Your compliance with, where applicable, the obligations of Privacy Laws, including data subject access requests, DPIAs and prior consultation;
  • e) Delete Personal Data promptly upon your request, or in absence of such request delete or anonymize all Personal Data no later than sixty (60) days after the end (in whole or in part) of the provision of Services under Agreement, and delete existing copies unless applicable law to which Origin is subject requires storage of Personal Data or unless copies of Personal Data have been created electronically pursuant to automatic or ordinary course archiving, back-up, security and such Personal Data will be permanently deleted in accordance with standard retention policies and will be treated in accordance with this DPA until permanently deleted;
  • f) Upon Your request: (1) make available to You all information reasonably necessary to demonstrate compliance with this DPA; and (2) allow for and contribute to audits, including inspections, conducted by You. In lieu of an on-site audit, Origin will, upon reasonable written request and subject to confidentiality obligations no less protective than those in the Agreement, make available a copy of its then-current SOC 2 Type II report. Such documentation shall be deemed to satisfy Your audit rights under this DPA, except where applicable Privacy Laws or a competent supervisory authority specifically require an on-site inspection; in that case, such inspection shall be conducted no more frequently than once per year, during normal business hours, on at least thirty (30) days’ prior written notice, by mutually approved independent auditors (who shall not be direct competitors of the Data Processor) bound by confidentiality. Each Party shall bear its own costs and expenses arising out of or in connection with the audit;
  • g) Immediately inform You if, in its opinion, an instruction from You infringes the GDPR or other Privacy Laws.

5. Your Obligations

5.1) You represent and warrant that You have provided all requisite information and notification to Data Subjects regarding the collection and processing of their Personal Data provided to Origin hereunder, as may be required under the Privacy Laws.

5.2) You acknowledge that Origin is not required to verify whether You have duly given any prior information/notification to the Data Subjects and duly obtained any consent thereof with respect to the Personal Data disclosed to Origin hereunder, and You shall bear all liability related thereto.

5.3) To the extent reasonably possible, You agree to take necessary measures to:

  • a) Ensure that any information about the Data Subjects that is disclosed/transferred to Origin under this DPA is de-personalized, anonymized and/or otherwise encrypted/hashed so as to no longer constitute “Personal Data” within the meaning of Privacy Laws by the time it is disclosed/transferred to Origin;
  • b) Ensure that any text typed by the end-user when using Origin’s Services, in particular when completing the registration or feedback form, shall not contain any Personal Data; and
  • c) Discontinue any data conduits from Origin to a third-party service or platform that You have linked to the Services or otherwise integrated into the Services and instructed Origin to transfer data to such third-party service or platform, immediately upon termination of the contractual relationship with such third-party service or platform.

5.4) You shall, without undue delay, inform Origin of any facts affecting the fulfillment of their obligations under this DPA.

6. Sub-Processing

6.1) You grant a general written authorization for Origin to engage a third party to process Personal Data (“Sub-Processor”) in accordance with this DPA. The Sub-Processors identified at www.originhq.com/legal/sub-processor-list are already engaged by Origin as of the date of the DPA.

6.2) Origin may, subject to compliance with this section, engage a Sub-Processor, or replace or change the role of an existing Sub-Processor, provided that it notifies You of any intended use of a new Sub-Processor (e-mail shall be deemed sufficient) (“Email Notification”) thirty (30) days in advance.

6.3) If you deem that the engagement of the new Sub-Processor would cause you to breach Privacy Laws, You have the right, with reasonable grounds, to object in writing to the proposed use of the relevant Sub-Processor within fifteen (15) days of receipt of the Email Notification. If You have legitimate objections to the appointment of the new Sub-Processor, the parties will work together in good faith to resolve the grounds for the objection. Origin may in particular choose not to use the intended Sub-Processor or engage the Sub-Processor only after reasonable corrective steps and / or measures requested by You are taken. If objection is not made within such time-period, then the engagement of the new Sub-Processor shall be deemed accepted.

6.4) Origin remains liable for any non-compliance by any Sub-Processor.

6.5) Origin shall, where it engages a Sub-Processor: (a) carry out appropriate due diligence on the sub-processor prior to engaging it; (b) only use a sub-processor that has provided sufficient guarantees to implement appropriate technical and organizational measures; (c) impose on the sub-processor, through a legally binding contract between Origin and sub-processor, data protection obligations equivalent in substance to those set out in this DPA and provide at least the same level of protection as provided for by this DPA; and (d) implement legally required transfer mechanisms (such as SCCs where applicable) for the transfers of Personal Data outside of the EU/EEA.

7. Data Transfers to other Service Providers

7.1) Within certain Service features or functionalities, You may instruct Origin to transfer certain Personal Data or other data to third parties who are Your separate service providers. Origin will enable such transfers as reasonably possible. Origin will discontinue these transfers any time upon Your specific written instruction. If You instruct Origin to discontinue these transfers, certain Service features or functionalities may not be available or fully functional.

8. International Data Transfers

8.1) During the provision of the Services under the Agreement, Origin may transfer Personal Data to a third country or an international organization. Origin shall comply with Privacy Laws and the transfer mechanisms allowed by the Privacy Laws in all such transfers.

8.2) To the extent Personal Data includes Personal Data from the EU and EEA by entering into the Agreement and this DPA, the Parties are deemed to have agreed to the SCCs, including their annexes, available at originhq.com/legal/scc, and the SCCs will apply to transfers to third countries that are not subject to an adequacy decision. To the extent the SCCs are entered into, the following options for Module 2 of the SCCs shall be used:

  • a) Clause 7. The optional docking does not apply.
  • b) Clause 9. Use of sub-processors Option 2: General written authorization is selected and the minimum time period for prior notice of sub-processor changes and the notification method have been agreed in section 6 of the DPA.
  • c) Clause 11. The optional language does not apply.
  • d) Clause 13. All square brackets are removed.
  • e) Clause 17. Option 1 is selected and the Parties agree that this shall be Irish law
  • f) Clause 18 (b). The Parties agree that any dispute arising from these Clauses shall be resolved by the courts of Ireland.
  • g) Annex 1 to this DPA contains the information required in Annex I of the SCCs;
  • h) Annex 2 to this DPA contains the information required in Annex II of the SCCs; and
  • i) Annex 3 to this DPA contains the information required in Annex III of the SCCs.

8.3) To the extent Personal Data includes personal data from the UK for the purposes of localizing the SCCs to United Kingdom law, the parties agree to the following:

  • a) The parties agree that the SCCs are deemed amended to the extent necessary that they operate for transfers from the United Kingdom to a third country and provide appropriate safeguards for transfers according to Article 46 of the UK GDPR. Such amendments include changing references to the GDPR to the UK GDPR and changing references to EU Member States to the United Kingdom.
  • b) The IDTA will apply to transfers of UK Personal Data protected by the UK GDPR and will be completed as follows:
    • i) Table 1 will be completed with the relevant information in Annex 1 of this DPA;
    • ii) Table 2 will be completed with the selected modules and clauses the SCCs as identified in section 8.2 of this DPA;
    • iii) Table 3 will be completed with the relevant information from Annexes 1, 2 and 3 of this DPA;
    • iv) In Table 4, both the data exporter and data importer may end the IDTA in accordance with the terms of the IDTA.

8.4) To the extent Personal Data includes personal data from Switzerland for the purposes of localizing the SCCs to Swiss law the following applies:

  • a) The parties adopt the GDPR standard for all data transfers, or the standard under Swiss law where it is higher.
  • b) The parties agree that the references to provisions of the GDPR in the SCCs are to be understood as references to the corresponding provisions of the Swiss Federal Data Protection Act in the version applicable at the moment of initiation of any dispute.
  • c) The term Member State, where used in the SCCs, also applies to Switzerland. In particular, this shall ensure that Data Subjects are not excluded from the possibility to sue for their rights in their place of habitual residence.
  • d) Clause 13 and Annex I(C): The competent authorities under Clause 13, and in Annex I(C), are the Federal Data Protection and Information Commissioner and, concurrently, the EEA member state authority identified above.
  • e) Clause 17: The Parties agree that the governing jurisdiction is the Member State in which the data exporter is established for claims under the GDPR and the substantive laws of Switzerland for claims under the Swiss Federal Data Protection Act.
  • f) Clause 18: Any dispute arising from these Clauses shall be resolved by the courts of Zurich, Switzerland. A Data Subject may also bring legal proceedings against the data exporter and/or data importer before the courts of the Member State in which he/she has his/her habitual residence. The Parties agree to submit themselves to the jurisdiction of such courts.

9. US Privacy Laws

9.1) To the extent Origin’s processing of Personal Data under the Agreement is subject to US Privacy Laws, the Parties acknowledge that Origin’s retention, use and disclosure of Personal Data authorized by Your instructions stated in this Agreement are integral to the Origin Services and the business relationship between the Parties.

9.2) Origin shall:

  • a) Use, retain, and disclose Personal Data only as necessary to perform the business purposes specified in this Agreement or as otherwise permitted by US Privacy Laws;
  • b) Comply with applicable obligations under US Privacy Laws and shall provide the same level of privacy protection as is required of a “service provider” or “contractor” under each applicable US Privacy Law;
  • c) Implement reasonable and appropriate technical and organizational measures designed to protect Personal Data against unauthorized or unlawful processing, access, use, or disclosure;
  • d) Notify You without undue delay if Origin determines it cannot meet its obligations under US Privacy Laws;
  • e) Cooperate with You to stop and remediate any unauthorized use of Personal Data.

9.3) Origin shall not:

  • a) Sell or share any Personal Data;
  • b) Retain, use or disclose any Personal Data for any purpose other than for the business purposes specified in the Agreement, including retaining, using, or disclosing the Personal Data for a commercial purpose other than the business purposes specified in the Agreement or as otherwise permitted by US Privacy Laws;
  • c) Combine the Personal Data received from You with Personal Data received from or on behalf another person, or Personal Data Origin collects from its own interaction with the consumer, except as otherwise permitted by US Privacy Laws;
  • d) De-identify or aggregate Personal Data unless the de-identification meets US Privacy Laws, and the output cannot be re-identified.

10. Security and Personal Data Breach

10.1) Origin shall implement technical and organizational measures to ensure the security and protection of the Personal Data, including protecting the Personal Data against a Personal Data Breach. In assessing the appropriate level of security, the Parties shall take due account of the state of the art, the costs of implementation, the nature, scope, context, and purposes of processing, and the risks involved for the Data Subjects. The measures implemented by Origin at the time of entering into this DPA are specified in the Agreement.

10.2) Notify You without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Personal Data Breach with respect to the Personal Data processed under this DPA. Origin shall reasonably assist You in fulfilling its and Controller’s obligations under Privacy Laws, including Articles 33 and 34 of GDPR, to notify the relevant supervisory authority and Data Subjects of a Personal Data Breach.

11. Government and Regulatory Requests

11.1) If Origin receives a legally binding request from any government, regulatory, or law enforcement authority for the disclosure of Personal Data processed under this DPA (“Government Request”), Origin shall:

  • a) to the extent permitted by applicable law, promptly notify You in writing of the Government Request prior to disclosing any Personal Data, and in any event as soon as reasonably practicable;
  • b) disclose only the minimum amount of Personal Data strictly required to comply with the Government Request; and
  • c) maintain a record of all Government Requests received.

11.2) Where Origin is prohibited by applicable law from notifying You of a Government Request, Origin shall use commercially reasonable efforts to have such prohibition lifted or to obtain the right to notify You and notify You as soon as it is legally permitted to do so.

11.3) Nothing in this section shall require Origin to act in contravention of applicable law or to incur any costs or liability in challenging a Government Request unless You have agreed in writing to reimburse such costs in advance.

12. Data Processor’s Remuneration

12.1) The Parties have agreed that the remuneration for processing the Personal Data under this DPA is included in the remuneration for the Services provided for in the Agreement.

13. Term and Termination

13.1) This DPA has been concluded for the duration of the Agreement, and it shall come into force on the date of the signature of the Agreement by both Parties.

13.2) In the event the obligations under this DPA are terminated, Origin shall delete the Personal Data belonging to You and delete all existing copies, subject to section 4.2 of this DPA. The obligations of this DPA shall continue as long as Origin processes Personal Data on your behalf.

13.3) Neither Party hereto is entitled to assign any of the rights and obligations under this DPA to third parties without the prior written consent of the other Party.

14. Order of Precedence

14.1) This DPA supplements the Agreement and unless otherwise stipulated herein, the provisions of the Agreement shall apply, including any exclusions and limitation of warranties and liabilities provided therein. Provisions in this DPA shall have precedence over any provisions of the Agreement relating to the processing of Personal Data by Origin, if any.

Last Updated October 1, 2026

Annex 1: Details of Processing

A. List of Parties

Data exporter(s):

Name:
You as defined in the Agreement
Address:
The address for the Customer as defined in the Agreement
Contact person’s name, position and contact details:
The contact person for the Customer as defined in the Agreement
Activities relevant to the data transferred under these Clauses:
The use of Platform as defined in the Agreement
Role (controller/processor):
Controller

Data importer(s):

Name:
Origin as defined in the Agreement
Address:
The address for Origin as defined in the Agreement
Contact person’s name, position and contact details:
The contact person for the Origin contracting entity as defined in the Agreement
Activities relevant to the data transferred under these Clauses:
The provision of Platform as defined in the Agreement
Role (controller/processor):
Processor

B. Description of Transfer

Categories of data subjects whose personal data is transferred
Categories of Data Subjects are primarily designated by You, based on how You choose to use the Services and the scope of access You grant to Origin, and may include, without limitation, any individuals whose Personal Data is uploaded to the Services which will typically include employees and business partners of You and other persons with whom You interact.
Categories of personal data transferred

The following categories of Personal Data may be included, without limitation:

  • Personal data submitted by You or on its behalf to the Services through account registration, the management console, support requests, integrations, or other Service inputs, which typically include identification data and Service-related data;
  • Personal data to which Origin gains access through the provision of the Services, which typically include endpoint telemetry and metadata collected by the Observability Agents (which may include device identifiers, hostnames, IP addresses, user-account identifiers, process names and command-line arguments, network connection metadata, authentication events, file paths, and security events and detections), and data contained in Your endpoints to which Origin gains access while performing continuous endpoint observability, behavioral monitoring, threat detection, log and telemetry collection, security analytics (including by means of machine-learning and other artificial-intelligence components), or for support purposes based on the scope of access You granted to Origin.
  • Personal data to which Origin gains access during the provision of support services.
  • The exact scope of personal data processed will always depend on the specific Services or Service features then available and used by You and the functionality of the Services that You decide to implement and utilize.
Sensitive data transferred (if applicable) and applied restrictions or safeguards that fully take into consideration the nature of the data and the risks involved, such as for instance strict purpose limitation, access restrictions (including access only for staff having followed specialised training), keeping a record of access to the data, restrictions for onward transfers or additional security measures.
No sensitive data is intended to be transferred.
The frequency of the transfer (e.g. whether the data is transferred on a one-off or continuous basis).
Continuous basis.
Nature of the processing
The nature of the processing may include any operation that Origin may perform on Personal Data or on sets of Personal Data when providing Services, which may include in particular processing of data provided by You within Your account and limited access by Origin to Personal Data accessible through the endpoints of Your infrastructure or during provision of support services, storage of telemetry, security events, agent traces, alerts, detections, and behavioral baselines necessary to deliver the Services, disclosure by transmission, alignment or combination, erasure or destruction of data (whether or not by automated means).
Purpose(s) of the data transfer and further processing
Personal data will be transferred from You to Origin for Origin to provide the Services.
The period for which the personal data will be retained, or, if that is not possible, the criteria used to determine that period
The duration of the Agreement.

C. Competent Supervisory Authority

Identify the competent supervisory authority/ies in accordance with Clause 13
The Irish Supervisory Authority is the competent authority.

Annex 2: Security Measures

Origin has implemented technical and organizational measures to ensure an appropriate level of security, taking into account the nature, scope, context, and purpose of the processing, as well as the risks for the rights and freedoms of natural persons. Further details of the implemented measures are available upon request.

Annex 3: Sub-processors

The details, and description of the processing for the sub-processors can be found at: www.originhq.com/legal/sub-processor-list.